Featured image of post Flatpak: version 1.18.4 released with six security fixes

Flatpak: version 1.18.4 released with six security fixes

Flatpak has been released in version 1.18.4.

Flatpak is a framework for distributing and sandboxing Linux applications, independent of the distribution in use.

This version closes six CVEs, including privileged overwrite and deletion of arbitrary files by malicious apps, exposure of authentication tokens when downloading from OCI repositories, and a possible denial of service via .desktop and D-Bus .service files.

Security fixes:

  • Prevent privileged overwrite of arbitrary files with an empty file or a symlink to /run/host/monitor/resolv.conf when a malicious app is installed (CVE-2026-97024, GHSA-8xgq-v545-vgvf; thanks to Sebastian Wick)
  • Prevent privileged deletion of arbitrary files when a malicious app is installed (CVE-2026-97023, GHSA-5p67-xh8x-rq54; thanks to Sebastian Wick)
  • When downloading apps or runtimes from an OCI repository that requires authentication, don’t make the authentication token visible to other users (CVE-2026-97025, GHSA-7rvf-rqr3-43j4; thanks to AISLE in cooperation with Red Hat)
  • Restrict permissions on temporary repository directories in /var/tmp/flatpak-cache-* (CVE-2026-97026, GHSA-r9w3-qx54-qvc8; thanks to AISLE in cooperation with Red Hat)
  • Filter .desktop and D-Bus .service files against an allowlist of fields, preventing denial of service and unintended interactions with host services (CVE-2026-97027, GHSA-v64f-hrwr-j4vh; thanks to Markus Göllnitz)
  • Prevent apps from sending signals to a process group that includes a parent process outside the app, causing denial of service by killing the desktop environment (CVE-2026-97029, GHSA-f3p8-vr7v-gxf2; thanks to Guthrie Armstrong, Coalition, Inc.)

Bug fixes:

  • Update Meson wrap subprojects for projects that are normally taken from the host system:
    • xdg-dbus-proxy 0.1.9 (CVE-2026-93676, CVE-2026-94422)
  • Improve hardening against symlink traversal, related to CVE-2026-97023 and CVE-2026-97024

Internal changes:

  • Add CVE IDs and reporter credits to 1.18.1’s NEWS entry
  • Remove unnecessary U+200E LEFT-TO-RIGHT MARK from some older NEWS entries

Flatpak

Source: GitHub

PlayingTux – Playing Games on Linux - since 1995.