Flatpak 1.18.4 Released With Fixes for Six Security Vulnerabilities
programming.dev
Flatpak 1.18.4 Released With Fixes for Six Security Vulnerabilities
>Flatpak 1.18.4 has been released as a security-focused update to the popular application sandboxing and distribution framework for Linux, addressing six newly disclosed vulnerabilities along with several related hardening improvements. > >Among the most important fixes is CVE-2026-97024, which could allow a malicious Flatpak application during installation to overwrite arbitrary files with either an empty file or a symlink. A related issue, CVE-2026-97023, could be abused to delete arbitrary files with elevated privileges. > >The release also fixes CVE-2026-97025, an issue affecting authenticated OCI repositories. Flatpak now ensures authentication tokens used when downloading applications or runtimes are not exposed to other local users. CVE-2026-97026 is addressed by restricting permissions on temporary repository directories under /var/tmp/flatpak-cache-*. > >Another fix, tracked as CVE-2026-97027, introduces stricter filtering of .desktop and D-Bus .service files against an allowlist of permitted fields. According to the developers, this prevents denial-of-service scenarios as well as unintended interactions with services running on the host system. > >Flatpak 1.18.4 also resolves CVE-2026-97029, which could allow an application to send signals to a process group containing a parent process outside its sandbox. In certain circumstances, this could result in denial of service by terminating the user’s desktop environment. > >Beyond those six vulnerabilities, the update refreshes the bundled xdg-dbus-proxy fallback to version 0.1.9, fixing CVE-2026-93676 and CVE-2026-94422. Flatpak also received additional protection against symlink traversal related to CVE-2026-97023 and CVE-2026-97024. > >Finally, given the number and nature of the security fixes included, users are advised to install the update as soon as it becomes available through their Linux distribution’s repositories. > >For more details, see the changelog
0 comments
No comments yet.