to smartthemes.de

Flatpak 1.18.1 Closes Ten Security Vulnerabilities

2 points 0

The Flatpak team has released Flatpak 1.18.1, an important security update for the cross-distribution application packaging system. Released on August 11, the new version fixes ten security vulnerabilities, several of which could potentially allow attackers to access the host system or escalate user privileges.
Users are strongly encouraged to update to Flatpak 1.18.1 as soon as possible.

Critical Security Issues

Among the most serious vulnerabilities is GHSA-8688-9×26-hhxj, which could allow an attacker to bypass the Flatpak sandbox through a symlink attack involving an application’s data directories. A successful exploit could provide read and write access to the host filesystem.

Another serious vulnerability in revokefs involved symlinks and path traversal. Under certain circumstances, it could allow a local attacker to escalate privileges all the way to root.

The update also addresses vulnerabilities involving extra-data, flatpak build-init and OCI archives. Some of these issues could have allowed files to be written to arbitrary locations with root privileges or enabled access to files outside their intended directories.
A buffer overflow affecting the processing of OCI delta streams on 32-bit systems has also been fixed. In addition, Flatpak 1.18.1 closes a vulnerability that could be used to bypass the downgrade protection for system-wide applications.

Bug Fixes and Improvements

Flatpak 1.18.1 is not limited to security fixes. The release also addresses several regular bugs and regressions.
Among the improvements are fixes for environment-variable handling in flatpak-spawn, crashes in the portal update monitor and problems when processing OCI JSON data. The developers have also improved handling of OCI signatures and TLS certificates, as well as Bash completion.

Flatpak 1.19.0 Pre-Release 

At the same time, the Flatpak developers have published Flatpak 1.19.0 as a pre-release for the next development branch.
Version 1.19.0 contains the same ten security fixes included in 1.18.1, while also introducing several new features. These include the ability to authorize system-wide downgrades through Polkit instead of requiring direct root privileges.
The development release also adds the flatpak-coredumpctl list command and a new API that allows frontends to access the current transfer speed.

Update Recommended

For users running Flatpak 1.18.x, updating to Flatpak 1.18.1 is highly recommended because several of the vulnerabilities affect the security boundary between sandboxed applications and the host system.
The 1.19.0 release, meanwhile, is aimed primarily at testing and development. Production systems should generally stick with the stable 1.18.1 release until the next stable branch becomes available.

August 13, 2026

Source https://linuxnews.de/

Edited 2 months ago

2 points 0
27 views
m/Jonas310

What do you think?

Read on