Skip to content

Releases: flatpak/flatpak

1.19.2

1.19.2 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 28 Sep 13:24
Immutable release. Only release title and notes can be modified.

This is a development prerelease from the 1.19.x series.
The first stable release from this branch will be 1.20.0.

Changes in 1.19.2

Bug fixes:

  • Use bubblewrap from our PPA in the CI pipeline for creating releases

Changes in 1.19.1

Security fixes:

  • Prevent privileged overwrite of arbitrary files with an empty file or a
    symlink to /run/host/monitor/resolv.conf when a malicious app is installed
    (CVE-2026-97024, GHSA-8xgq-v545-vgvf; thanks to Sebastian Wick)

  • Prevent privileged deletion of arbitrary files when a malicious app
    is installed
    (CVE-2026-97023, GHSA-5p67-xh8x-rq54; thanks to Sebastian Wick)

  • When downloading apps or runtimes from an OCI repository that requires
    authentication, don't make the authentication token visible to other users
    (CVE-2026-97025, GHSA-7rvf-rqr3-43j4; thanks to AISLE in cooperation
    with Red Hat)

  • Restrict permissions on temporary repository directories in
    /var/tmp/flatpak-cache-*
    (CVE-2026-97026, GHSA-r9w3-qx54-qvc8; thanks to AISLE in cooperation
    with Red Hat)

  • Filter .desktop and D-Bus .service files against an allowlist of fields,
    preventing denial of service and unintended interactions with host services
    (CVE-2026-97027, GHSA-v64f-hrwr-j4vh; thanks to Markus Göllnitz)

  • Prevent apps from sending signals to a process group that includes a
    parent process outside the app, causing denial of service by killing
    the desktop environment
    (CVE-2026-97029, GHSA-f3p8-vr7v-gxf2; thanks to Guthrie Armstrong,
    Coalition, Inc.)

Build-system changes:

  • libglnx and variant-schema-compiler are now Meson wrap subprojects,
    not git subtrees.
    Official source release tarballs include a matching version of these
    subprojects.
    If building from git in an environment where subprojects cannot be
    downloaded automatically, please refer to Meson documentation.

Enhancements:

  • flatpak list --bytes, -b lists sizes in bytes

  • flatpak remote-info and flatpak remote-ls --updates update the local
    AppStream cache before showing information, unless the --cached option
    is used (#5974)

  • When displaying download size estimates for apps or runtimes that use
    the extra-data mechanism to download non-redistributable data out-of-band
    (such as Google Chrome), include the size of the extra data in the estimate
    (#5947)

  • Add new API flatpak_user_data_delete() so that app management UIs
    can implement the equivalent of flatpak uninstall --delete-data
    (#6728)

Bug fixes:

  • Update Meson wrap subprojects for projects that are normally taken from
    the host system:

    • bubblewrap 0.12.0 (CVE-2026-87766)
    • xdg-dbus-proxy 0.1.9 (CVE-2026-93676, CVE-2026-94422)
  • Improve hardening against symlink traversal, related to
    CVE-2026-97023 and CVE-2026-97024

  • Validate GVariant structure of summaries before using generated variant
    readers (#6779)

  • Fix crash in system helper when iterating cache directories (#6780)

  • Avoid corrupted output from non-UTF-8 characters in error messages (#6795)

  • Fix portal passing wrong file descriptor when sandbox-expose-fd-ro
    triggers fd remapping collision (#6785)

  • Fix system helper tracking wrong D-Bus sender for pulls (#6781)

  • Fix extensions not being populated in the sandbox due to unhandled
    EAGAIN from openat2 (#6787)

  • Fix build failure with GLib versions older than 2.72 (#6775)

  • Fix alignment of columns next to a decimal column (#4917)

  • Fix subsandbox startup (flatpak-spawn) when run from an app that
    was configured with --no-talk-name or --system-no-talk-name (#6776)

  • Fix a crash when a bundle is installed with explicit key bytes (#6842)

  • Fix a crash in flatpak document-export --noexist (#6847)

  • Make flatpak remote-add --no-follow-redirect,
    flatpak remote-modify --no-follow-redirect,
    flatpak remote-modify --follow-redirect work as intended (#6844)

  • Validate cursor position when emitting bash/zsh completions (#6761)

  • When listing subsets in flatpak repo --branches, correctly de-duplicate
    subsets whose names end with the name of a different subset (#6825)

  • Fix the ability to pass arguments via file forwarding if the host system
    uses an $XDG_RUNTIME_DIR that is not the conventional
    /run/user/$(id -u) (#6848)

  • Fix compiler warnings (#6849)

  • Test infrastructure improvements (#6794, #6796)

  • Documentation updates (manual page fixes, code of conduct,
    contributor guidelines)

  • Translation updates: ka, nn, pt_BR, sl, zh_CN

Internal changes:

  • Translation updates should now be contributed through GNOME's l10n
    platform, not as direct pull requests on Github.

  • Add CVE IDs and reporter credits to 1.19.0's NEWS entry

  • Remove unnecessary U+200E LEFT-TO-RIGHT MARK from some older NEWS entries

1.18.4

Choose a tag to compare

@github-actions github-actions released this 28 Sep 13:04
Immutable release. Only release title and notes can be modified.

Security fixes:

  • Prevent privileged overwrite of arbitrary files with an empty file or a
    symlink to /run/host/monitor/resolv.conf when a malicious app is installed
    (CVE-2026-97024, GHSA-8xgq-v545-vgvf; thanks to Sebastian Wick)

  • Prevent privileged deletion of arbitrary files when a malicious app
    is installed
    (CVE-2026-97023, GHSA-5p67-xh8x-rq54; thanks to Sebastian Wick)

  • When downloading apps or runtimes from an OCI repository that requires
    authentication, don't make the authentication token visible to other users
    (CVE-2026-97025, GHSA-7rvf-rqr3-43j4; thanks to AISLE in cooperation
    with Red Hat)

  • Restrict permissions on temporary repository directories in
    /var/tmp/flatpak-cache-*
    (CVE-2026-97026, GHSA-r9w3-qx54-qvc8; thanks to AISLE in cooperation
    with Red Hat)

  • Filter .desktop and D-Bus .service files against an allowlist of fields,
    preventing denial of service and unintended interactions with host services
    (CVE-2026-97027, GHSA-v64f-hrwr-j4vh; thanks to Markus Göllnitz)

  • Prevent apps from sending signals to a process group that includes a
    parent process outside the app, causing denial of service by killing
    the desktop environment
    (CVE-2026-97029, GHSA-f3p8-vr7v-gxf2; thanks to Guthrie Armstrong,
    Coalition, Inc.)

Bug fixes:

  • Update Meson wrap subprojects for projects that are normally taken from
    the host system:

    • xdg-dbus-proxy 0.1.9 (CVE-2026-93676, CVE-2026-94422)
  • Improve hardening against symlink traversal, related to
    CVE-2026-97023 and CVE-2026-97024

Internal changes:

  • Add CVE IDs and reporter credits to 1.18.1's NEWS entry

  • Remove unnecessary U+200E LEFT-TO-RIGHT MARK from some older NEWS entries

1.18.3

Choose a tag to compare

@github-actions github-actions released this 22 Sep 11:07
Immutable release. Only release title and notes can be modified.

Bug fixes:

  • Update Meson wrap subprojects for projects that are normally taken from
    the host system:

    • bubblewrap 0.12.0 (CVE-2026-87766)
    • xdg-dbus-proxy 0.1.8 (CVE-2026-93676)
  • Fix regressions in 1.18.2 when building apps/runtimes, especially on
    SELinux systems or when the runtime is not installed per-user
    (#6818)

  • Fix subsandbox startup (flatpak-spawn) when run from an app that
    was configured with --no-talk-name or --system-no-talk-name (#6776)

  • Fix a crash when a bundle is installed with explicit key bytes (#6842)

  • Documentation updates (code of conduct, contributor guidelines)

1.18.2

Choose a tag to compare

@github-actions github-actions released this 27 Aug 19:47
Immutable release. Only release title and notes can be modified.

Bug fixes:

  • Validate GVariant structure of summaries before using generated variant
    readers (#6779)

  • Fix crash in system helper when iterating cache directories (#6780)

  • Avoid corrupted output from non-UTF-8 characters in error messages (#6795)

  • Fix portal passing wrong file descriptor when sandbox-expose-fd-ro
    triggers fd remapping collision (#6785)

  • Fix system helper tracking wrong D-Bus sender for pulls (#6781)

  • Fix extensions not being populated in the sandbox due to unhandled
    EAGAIN from openat2 (#6787)

  • Fix build failure with GLib versions older than 2.72 (#6777)

  • Test infrastructure improvements (#6794, #6796)

1.19.0

1.19.0 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 11 Aug 12:29
Immutable release. Only release title and notes can be modified.

Security fixes:

  • Fix sandbox escape with full host filesystem read/write access via symlink
    attack on app data directories (GHSA-8688-9x26-hhxj)

  • Fix local root privilege escalation via revokefs symlink path traversal and
    commit tampering (GHSA-qrwq-7qwx-q9rp)

  • Fix arbitrary root write via symlink and path traversal in extra-data
    extraction (GHSA-fqx6-vh4p-42cg)

  • Fix arbitrary root write via path traversal in flatpak build-init
    (GHSA-8qxj-x646-phcm)

  • Fix arbitrary host file read via hardlink path traversal in OCI archive
    extraction (GHSA-9rww-v4mm-x4jg)

  • Fix path traversal via unvalidated architecture parameter in DeployAppstream
    (GHSA-v2gw-v9h5-9q4x)

  • Fix buffer overflow in OCI delta stream path names on 32-bit systems
    (GHSA-jr92-2v97-wgvc)

  • Fix fixed-filename writes to arbitrary locations via symlink attack on .ld.so
    (GHSA-99wv-m8rp-g58x)

  • Fix extension metadata path traversal allowing host filesystem probing and
    unintended mount locations (GHSA-w69g-9x8j-7p8f)

  • Fix anti-downgrade bypass allowing unprivileged users to downgrade system
    apps (GHSA-q4gr-vc25-57m5)

Enhancements:

  • Allow system-wide downgrades through the system helper, authenticated via
    new polkit actions instead of requiring root (#6669)

  • Add flatpak-coredumpctl list subcommand and Bash completion for
    flatpak-coredumpctl (#6705, #6678, #6677)

  • Add flatpak_transaction_progress_get_bytes_per_second() to the library API
    (#6679)

  • Lock the session helper's runtime directory to prevent systemd-tmpfiles from
    cleaning the p11-kit socket (#6754)

  • Check OCI signatures from the mirrored repo in the system helper instead of
    fetching them from the lookaside server (#6682)

  • Cleanup of Bash completion (#6710)

  • Translation updates: pt_BR (#6701, #6751), sl (#6726), sv (#6750), uk
    (#6715), zh_CN (#6748)

Bug fixes:

  • Fix portal flatpak-spawn environment handling regression (#6721)

  • Don't set no_interaction for --assumeyes, so that credential and polkit
    prompts still work (#6744)

  • Fix the inverted behavior of --clear-env (#6722)

  • Fix negated permission strings for allow and share run options (#6684, #6687)

  • Error out if file forwarding of empty paths is attempted (#6693)

  • Fix build failure when exporting metainfo releases.xml files (#6698)

  • Fix crashes in the portal update monitor (#6692) and OCI JSON handling
    (#6704)

  • Fix GI annotation for flatpak_instance_get_all (#6696)

  • Apply TLS certs to OCI registry requests and propagate stream write failures
    to curl (#6685)

  • Harden the system helper by validating remote names, dropping supplementary
    groups, and not logging credentials (#6722, #6724)

  • Numerous fixes for crashes, memory leaks, integer overflows, and error
    handling (#6722, #6724, #6723, #6713, #6725)

  • Test, CI, and documentation improvements (#6681, #6742, #6711, #6712, #6752,
    #6755)

1.18.1

Choose a tag to compare

@github-actions github-actions released this 11 Aug 12:59
Immutable release. Only release title and notes can be modified.

Security fixes:

  • Fix sandbox escape with full host filesystem read/write access via symlink
    attack on app data directories (GHSA-8688-9x26-hhxj)

  • Fix local root privilege escalation via revokefs symlink path traversal and
    commit tampering (GHSA-qrwq-7qwx-q9rp)

  • Fix arbitrary root write via symlink and path traversal in extra-data
    extraction (GHSA-fqx6-vh4p-42cg)

  • Fix arbitrary root write via path traversal in flatpak build-init
    (GHSA-8qxj-x646-phcm)

  • Fix arbitrary host file read via hardlink path traversal in OCI archive
    extraction (GHSA-9rww-v4mm-x4jg)

  • Fix path traversal via unvalidated architecture parameter in DeployAppstream
    (GHSA-v2gw-v9h5-9q4x)

  • Fix buffer overflow in OCI delta stream path names on 32-bit systems
    (GHSA-jr92-2v97-wgvc)

  • Fix fixed-filename writes to arbitrary locations via symlink attack on .ld.so
    (GHSA-99wv-m8rp-g58x)

  • Fix extension metadata path traversal allowing host filesystem probing and
    unintended mount locations (GHSA-w69g-9x8j-7p8f)

  • Fix anti-downgrade bypass allowing unprivileged users to downgrade system
    apps (GHSA-q4gr-vc25-57m5)

Bug fixes:

  • Fix portal flatpak-spawn environment handling regression (#6721)

  • Fix negated permission strings for allow and share run options (#6684)

  • Fix build failure when exporting metainfo releases.xml files (#6698)

  • Fix crashes in the portal update monitor (#6692) and OCI JSON handling
    (#6704)

  • Error out if file forwarding of empty paths is attempted (#6693)

  • Check OCI signatures from the mirrored repo in the system helper instead of
    fetching from the lookaside server (#6682)

  • Apply TLS certs to OCI registry requests and propagate stream write failures
    to curl (#6685)

  • Fix GI annotation for flatpak_instance_get_all (#6696)

  • Cleanup of Bash completion (#6710)

  • Numerous internal fixes for crashes, error handling, and hardening (#6723,
    #6725)

1.18.0

Choose a tag to compare

@github-actions github-actions released this 08 Jun 12:45
Immutable release. Only release title and notes can be modified.

Enhancements:

  • Improve error handling and printed output of flatpak-coredumpctl (#6649,
    #6680)

  • Support the AMD vendor specific compute interface (/dev/kfd) via the DRI
    device permission (#6648)

  • Improve the output of flatpak update with failure causes (#6657)

  • Improve startup time for fish shell integration (#6635)

  • Translation updates: ‎zh_CN (#6671)

Bug fixes:

  • Fix building when HAVE_LIBSYSTEMD but not USE_SYSTEM_HELPER is defined (#6652)

  • Ignore system bus failures in parental controls check (#6663)

  • Fix some return values and replace deprecated GTimeVal with
    g_get_real_time() (#6646)

  • Suppress an unused-result warning in the tests (#6655)

1.17.7

1.17.7 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 05 May 22:55
Immutable release. Only release title and notes can be modified.

Enhancements:

  • Add the new permission conditionals has-usb-device and has-usb-portal to
    allow apps to drop --device=all and --device=usb permissions (#6560)

  • Always send the Flatpak-Upgrade-From header when updating instead of
    freshly installing, to improve the quality of statistics (#6626)

  • Improve how the absence of the system repo is handled (#6621)

  • Changes to repos are now more atomic which helps to avoid them being in an
    invalid state. This could be observed when importing the GPG key failed,
    because the system clock was wrong. (#6547)

  • A function to report the age of the configuration was added to libflatpak,
    which will help GNOME Software to prevent unnecessary work (#6532)

  • Improvements to the build system (#6614, #6610)

  • Improve various tests (#6604, #6606, #6619, #6617, #6605, #6625)

  • Translation updates: tr (#6629), ‎zh_CN (#6630)

Bug fixes:

  • Fix a regression in handling of the fallback-x11 permission, which was
    affecting overrides from Flatseal (#6632)

  • Fix a memory leak in the Flatpak portal (#6613)

  • Install SELinux configuration files to the right directory (#6622)

  • Silence wrong lseek() errors when creating sub-sandboxes (#6609)

1.17.6

1.17.6 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 10 Apr 17:58
Immutable release. Only release title and notes can be modified.

Bug fixes:

  • Fix the remaining regression for Chromium based browsers by not leaking file
    descriptors down to wrapped command (#6589, #6594)

  • Fix a regression when installing extra-data without a runtime, which is the
    case for openh264 (#6587)

  • Fix the remaining regression for Epiphany by ignoring unusable sandbox-expose
    paths for sub-sandboxes in the portal (#6588)

  • Fix the installed tests by allowing to add a new ref to an existing temporary
    ostree repo (#6592)

  • Avoid closing fds 0/1/2 when they are used as a bad argument to flatpak-run,
    and reduce duplication in handling file descriptor arguments (#6598)

Enhancements:

  • Disable auto-pin in flatpak-repair to preserve the pin state across
    re-installs (#6571)

  • Small improvements for the tests (#6596, #6595, #6597)

1.16.6

Choose a tag to compare

@swick swick released this 10 Apr 17:40
Immutable release. Only release title and notes can be modified.

Bug fixes:

  • Fix the remaining regression for Chromium based browsers by not leaking file
    descriptors down to wrapped command (#6589, #6594)

  • Fix a regression when installing extra-data without a runtime, which is the
    case for openh264 (#6587)

  • Fix the remaining regression for Epiphany by ignoring unusable sandbox-expose
    paths for sub-sandboxes in the portal (#6588)

  • Fix the installed tests by allowing to add a new ref to an existing temporary
    ostree repo (#6592)

  • Avoid closing fds 0/1/2 when they are used as a bad argument to flatpak-run,
    and reduce duplication in handling file descriptor arguments (#6598)


1e63e7f3fe44b602f34d92a6fe46fd8a3bc6be9460c03c2681e57976c658eec3 *flatpak-1.16.6.tar.xz