Flatpak wurde in Version 1.18.4 veröffentlicht.
Flatpak ist ein Framework zur Verteilung und Sandbox-Isolation von Linux-Anwendungen, unabhängig von der genutzten Distribution.
Die Version schließt sechs CVEs, unter anderem das Überschreiben und Löschen beliebiger Dateien mit erhöhten Rechten durch bösartige Apps, das Auslesen von Auth-Tokens beim Download aus OCI-Repositories sowie einen möglichen Denial-of-Service über .desktop- und D-Bus-.service-Dateien.
Security fixes:
- Prevent privileged overwrite of arbitrary files with an empty file or a symlink to /run/host/monitor/resolv.conf when a malicious app is installed (CVE-2026-97024, GHSA-8xgq-v545-vgvf; thanks to Sebastian Wick)
- Prevent privileged deletion of arbitrary files when a malicious app is installed (CVE-2026-97023, GHSA-5p67-xh8x-rq54; thanks to Sebastian Wick)
- When downloading apps or runtimes from an OCI repository that requires authentication, don’t make the authentication token visible to other users (CVE-2026-97025, GHSA-7rvf-rqr3-43j4; thanks to AISLE in cooperation with Red Hat)
- Restrict permissions on temporary repository directories in /var/tmp/flatpak-cache-* (CVE-2026-97026, GHSA-r9w3-qx54-qvc8; thanks to AISLE in cooperation with Red Hat)
- Filter .desktop and D-Bus .service files against an allowlist of fields, preventing denial of service and unintended interactions with host services (CVE-2026-97027, GHSA-v64f-hrwr-j4vh; thanks to Markus Göllnitz)
- Prevent apps from sending signals to a process group that includes a parent process outside the app, causing denial of service by killing the desktop environment (CVE-2026-97029, GHSA-f3p8-vr7v-gxf2; thanks to Guthrie Armstrong, Coalition, Inc.)
Bug fixes:
- Update Meson wrap subprojects for projects that are normally taken from the host system:
- xdg-dbus-proxy 0.1.9 (CVE-2026-93676, CVE-2026-94422)
- Improve hardening against symlink traversal, related to CVE-2026-97023 and CVE-2026-97024
Internal changes:
- Add CVE IDs and reporter credits to 1.18.1’s NEWS entry
- Remove unnecessary U+200E LEFT-TO-RIGHT MARK from some older NEWS entries

Quelle: GitHub