Flatpak 1.18.4 Released With Important Security Fixes
([Desktop] 3 Hours Ago
Flatpak 1.18.4)
- Reference: 0001660503
- News link: https://www.phoronix.com/news/Flatpak-1.18.4-Released
- Source link:
Flatpak 1.18.4 is out today with a number of high profile security fixes for this app sandboxing and distribution tech.
Flatpak 1.18.4 fixes a security issue to prevent privileged overwrite of arbitrary files with an empty file or a symlink to /run/host/monitor/resolv.conf by malicious apps. There is also another security issue addressed to prevent the privileged deletion of arbitrary files by malicious apps.
There is also a fix when downloading apps or runtimes from an OCI repository with authentication that the authentication tokens would be visible to other users.
Flatpak 1.18.4 is also now filtering .desktop and D-Bus .service files against an allow-list of fields to prevent potential denial of service and unintended interactions with host services. Another denial of service addressed is to prevent apps from sending signals to a process group that includes parent processes outside the app, which could cause a denial of service by killing the desktop environment.
These plus other security fixes are all now bundled up in [1]Flatpak 1.18.4 . Also out today is [2]Flatpak 1.19.2 as the newest development version with these security fixes added.
[1] https://github.com/flatpak/flatpak/releases/tag/1.18.4
[2] https://github.com/flatpak/flatpak/releases/tag/1.19.2
Flatpak 1.18.4 fixes a security issue to prevent privileged overwrite of arbitrary files with an empty file or a symlink to /run/host/monitor/resolv.conf by malicious apps. There is also another security issue addressed to prevent the privileged deletion of arbitrary files by malicious apps.
There is also a fix when downloading apps or runtimes from an OCI repository with authentication that the authentication tokens would be visible to other users.
Flatpak 1.18.4 is also now filtering .desktop and D-Bus .service files against an allow-list of fields to prevent potential denial of service and unintended interactions with host services. Another denial of service addressed is to prevent apps from sending signals to a process group that includes parent processes outside the app, which could cause a denial of service by killing the desktop environment.
These plus other security fixes are all now bundled up in [1]Flatpak 1.18.4 . Also out today is [2]Flatpak 1.19.2 as the newest development version with these security fixes added.
[1] https://github.com/flatpak/flatpak/releases/tag/1.18.4
[2] https://github.com/flatpak/flatpak/releases/tag/1.19.2