Format: 1.8
Date: Tue, 11 Aug 2026 10:22:54 +0100
Binary: flatpak flatpak-dbgsym flatpak-tests flatpak-tests-dbgsym gir1.2-flatpak-1.0 libflatpak0 libflatpak0-dbgsym libflatpak-dev libflatpak-doc
Source: flatpak
Architecture: all amd64 source
Version: 1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67
Distribution: UNRELEASED
Urgency: high
Maintainer: Utopia Maintenance Team <pkg-utopia-maintainers@lists.alioth.debian.org>
Changed-By: Snapshot <snapshot@localhost>
Description: 
 flatpak    - Application deployment framework for desktop apps
 flatpak-tests - Application deployment framework for desktop apps (tests)
 gir1.2-flatpak-1.0 - Application deployment framework for desktop apps (introspection)
 libflatpak0 - Application deployment framework for desktop apps (library)
 libflatpak-dev - Application deployment framework for desktop apps (development)
 libflatpak-doc - Application deployment framework for desktop apps (documentation)
Changes:
 flatpak (1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67) UNRELEASED; urgency=high
 .
   * Snapshot build (local package)
 .
   [ Simon McVittie ]
   * d/patches: Backport security fixes from 1.18.1
     - d/p/libglnx/*.patch:
       Backport glnx_chase_and_mkdirat() utility function, required by some
       of the security fixes below
     - d/p/tests/*.patch:
       Backport unit tests fixes which are required by the tests for some
       of the security fixes below
     - d/p/GHSA-fqx6-vh4p-42cg-GHSA-8qxj-x646-phcm/*.patch:
       + GHSA-fqx6-vh4p-42cg:
         Fix writing outside installation directory via crafted commit metadata.
         A malicious or compromised Flatpak repository could write
         attacker-controlled files outside /var/lib/flatpak as root.
       + GHSA-8qxj-x646-phcm:
         Fix writing outside working directory in `flatpak build-init`.
         A malicious or compromised SDK could write outside the intended
         working directory when a developer starts using it for a build.
     - d/p/GHSA-qrwq-7qwx-q9rp/*.patch:
       Fix local privilege escalation involving revokefs.
       A malicious local user could write files outside /var/lib/flatpak
       as root by tampering with OSTree objects after signature verification.
     - d/p/GHSA-8688-9x26-hhxj/*.patch:
       Fix a sandbox escape involving directories inside ~/.var/app/APP_ID.
       A malicious or compromised Flatpak app could write to arbitrary files
       outside its sandbox.
     - d/p/GHSA-99wv-m8rp-g58x/*.patch:
       Fix a sandbox escape involving the ld.so cache.
       A malicious or compromised Flatpak app could write files with a fixed
       name and limited control over content outside the sandbox.
     - d/p/GHSA-v2gw-v9h5-9q4x/*.patch:
       Fix local privilege escalation involving crafted OCI architecture names.
       A malicious local user on a system with an OCI remote configured
       (unusual on non-Fedora systems) could trick the flatpak-system-helper
       process into writing outside /var/lib/flatpak.
     - d/p/GHSA-w69g-9x8j-7p8f/*.patch:
       Fix reading outside sandbox involving crafted extension metadata.
       A malicious or compromised Flatpak app could find out whether specific
       files exist outside the sandbox.
     - d/p/GHSA-q4gr-vc25-57m5/*.patch:
       Fix anti-downgrade checks for components installed system-wide.
       A malicious local user with an active local login session could
       downgrade an app, runtime or extension to an older, known-vulnerable
       version and use this to attack other local users.
     - d/p/GHSA-jr92-2v97-wgvc/*.patch:
       Fix a buffer overflow when installing or updating from a malicious OCI
       registry, not believed to be practically exploitable on 64-bit systems.
     - d/p/hardening/*.patch:
       Harden file accesses against path traversal, fixing issues that
       were initially thought to be security vulnerabilities similar to
       those above, but on further analysis do not seem to be exploitable.
     - d/p/GHSA-r7hp-698j-2h6c/*.patch:
       Correct xdg-dbus-proxy rules for receiving selected AT-SPI broadcasts
       so that GTK accessibility features work as intended.
       Previously, these accessibility features only worked accidentally as a
       result of an xdg-dbus-proxy security issue, fixed in 0.1.8.
   * d/patches: Add additional bug fixes from upstream 1.16.x branch
     - d/p/subprojects-Ignore-.wraplock-file-generated-by-recent-Mes.patch,
       d/p/bwrap-Clarify-a-comment.patch,
       d/p/subprojects-Update-dbus-proxy.wrap-to-v0.1.7.patch:
       Resync with upstream source, no functional changes
     - d/p/dir-Use-flatpak_bwrap_child_setup_inherit_fds_cb-to-apply.patch:
       Silence a spurious warning when apps use the extra_data mechanism
     - d/p/portal-Actually-use-the-AppInfo-hash-table.patch:
       Fix a memory leak and potential rare crashes in flatpak-portal
 .
   [ Snapshot ]
   * snapshot: commit f6f0dee67 (4 commits after 1.16.6-1~deb13u1)
Checksums-Sha1: 
 d2a7b400b6c13407bf585c86399bb7eaa123d64c 2950 flatpak_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67.dsc
 9d8152df1caa181817e11f47eb37443c59ce7c00 76532 flatpak_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67.debian.tar.xz
 427fd5b59acba423d61d8559179773cc99160d72 14493 flatpak_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_source.buildinfo
 2f2e013639299ff48ce4fdbb8ac0206b48b9a7b0 7701192 flatpak-dbgsym_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_amd64.deb
 884e6e12adfa8377f20df65f71cb1a04e721a288 10992368 flatpak-tests-dbgsym_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_amd64.deb
 abcb9cd366cdc59598ade28cdfbdf76164c392bd 1451944 flatpak-tests_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_amd64.deb
 dc6771cac3733c122309d6a9c172b3734a1c9d06 17195 flatpak_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_amd64.buildinfo
 6ab604abedaa809778b203f16ac6904249ff585d 1551212 flatpak_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_amd64.deb
 28135039f3058d559f20fd0d68cb89e5643483ea 29460 gir1.2-flatpak-1.0_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_amd64.deb
 8b64596df1701bf4878abef55eefd876fa25b905 73756 libflatpak-dev_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_amd64.deb
 edacc5f7cfd2c1657481622e83698dc1413492b8 1764344 libflatpak0-dbgsym_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_amd64.deb
 1cfd12ce5f57490022e7721cb5de5512dce0d52d 394868 libflatpak0_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_amd64.deb
 0435b1cc158953e32142b0303c18206d80cd2a20 14619 flatpak_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_all.buildinfo
 8899566531991d532e73688d91ec64700596295f 166212 libflatpak-doc_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_all.deb
Checksums-Sha256: 
 e97393b865c14cf28d832bd6f41501d573ef3f347044e2ba025c3bf32fe6ee76 2950 flatpak_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67.dsc
 75b90a3b7113300ffce526e69899bf07250aa9ed052096622a20b771025aa543 76532 flatpak_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67.debian.tar.xz
 862f598392577e50fcc5c248c0054eeffdd0e5b7752329826fb5a0ab404d77a1 14493 flatpak_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_source.buildinfo
 e01439b2f2e0c98cf75a55279ff995d9789ec5a67cf73888d87517ea50e7aa19 7701192 flatpak-dbgsym_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_amd64.deb
 f22d972bbec6755b3d35c576292fe7146ccab448b1eb51f2d8a4419d8732622c 10992368 flatpak-tests-dbgsym_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_amd64.deb
 40b4a880af332f4a336e224d09f344732a7440b231d2fe22510ec87b3eb73293 1451944 flatpak-tests_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_amd64.deb
 567e803062b1d1622c1d2ad447d5d2c4525601f1530ef9517c1a07a7f2ffbcf6 17195 flatpak_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_amd64.buildinfo
 8c46f2198538ee1e119346fbb11dc74f2b0e1387212f823a9abb40a1acf366d6 1551212 flatpak_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_amd64.deb
 ab331e3ccfbb7196b2fa16f595969199b4f86a546ac6e30923de2fd4ad4423ba 29460 gir1.2-flatpak-1.0_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_amd64.deb
 eefb8e96a4fc0c76a7ed78efe2558d645eeb8657161484551a984213dff4285a 73756 libflatpak-dev_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_amd64.deb
 f4b51fd86cb3b1be030151c16ac6ccde5b8b9d15ed56be296eb885c84cb9cff5 1764344 libflatpak0-dbgsym_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_amd64.deb
 ec0a57c708b200a4d6cd3108ea204913ab66ca07e895f292fdc8a6a592c4710e 394868 libflatpak0_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_amd64.deb
 e4b9f2b48d0881d17e16dc41f38f556f663a5d97dda20d4f3f593f28e4100abd 14619 flatpak_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_all.buildinfo
 6b9999a85fd0b7628cf4b34806e59cc280c6c78d815512a7796df97068846033 166212 libflatpak-doc_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_all.deb
Files: 
 de73168d04844069c30205e0c3fd990e 2950 admin optional flatpak_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67.dsc
 4371e4774198fae0708d77dc0e632702 76532 admin optional flatpak_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67.debian.tar.xz
 032ff01b401e73a4e5bb77b0a03351d9 14493 admin optional flatpak_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_source.buildinfo
 2443a716df2ab745cf6ca836b72f1b78 7701192 debug optional flatpak-dbgsym_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_amd64.deb
 2ed96c6c85cae827f49743cd641ec4bd 10992368 debug optional flatpak-tests-dbgsym_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_amd64.deb
 6b3af5735afe18e57ccb0e0e4fbd3435 1451944 misc optional flatpak-tests_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_amd64.deb
 b26714132556354a57e0ab479e279c2d 17195 admin optional flatpak_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_amd64.buildinfo
 2a3c5c1f8f59095397c04e9c65341b3e 1551212 admin optional flatpak_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_amd64.deb
 a07ae8bd923274728dafb8aafd3f14f1 29460 introspection optional gir1.2-flatpak-1.0_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_amd64.deb
 eac6350c74e323cec4682f0e58a1714f 73756 libdevel optional libflatpak-dev_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_amd64.deb
 3e41da7a0c6d5a86afabbf1cb5e78ef2 1764344 debug optional libflatpak0-dbgsym_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_amd64.deb
 5488b663e497421328c2cf404fb115a1 394868 libs optional libflatpak0_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_amd64.deb
 938dd80deebc966724ff0f94f2bbeec1 14619 admin optional flatpak_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_all.buildinfo
 612957a6630308b12fb245e3054d593c 166212 doc optional libflatpak-doc_1.16.6-1~deb13u2~1~deb13u1+4+gf6f0dee67_all.deb
