Repository navigation
Releases: flatpak/flatpak
Release list
1.19.2
This is a development prerelease from the 1.19.x series.
The first stable release from this branch will be 1.20.0.
Changes in 1.19.2
Bug fixes:
- Use bubblewrap from our PPA in the CI pipeline for creating releases
Changes in 1.19.1
Security fixes:
-
Prevent privileged overwrite of arbitrary files with an empty file or a
symlink to /run/host/monitor/resolv.conf when a malicious app is installed
(CVE-2026-97024, GHSA-8xgq-v545-vgvf; thanks to Sebastian Wick) -
Prevent privileged deletion of arbitrary files when a malicious app
is installed
(CVE-2026-97023, GHSA-5p67-xh8x-rq54; thanks to Sebastian Wick) -
When downloading apps or runtimes from an OCI repository that requires
authentication, don't make the authentication token visible to other users
(CVE-2026-97025, GHSA-7rvf-rqr3-43j4; thanks to AISLE in cooperation
with Red Hat) -
Restrict permissions on temporary repository directories in
/var/tmp/flatpak-cache-*
(CVE-2026-97026, GHSA-r9w3-qx54-qvc8; thanks to AISLE in cooperation
with Red Hat) -
Filter .desktop and D-Bus .service files against an allowlist of fields,
preventing denial of service and unintended interactions with host services
(CVE-2026-97027, GHSA-v64f-hrwr-j4vh; thanks to Markus Göllnitz) -
Prevent apps from sending signals to a process group that includes a
parent process outside the app, causing denial of service by killing
the desktop environment
(CVE-2026-97029, GHSA-f3p8-vr7v-gxf2; thanks to Guthrie Armstrong,
Coalition, Inc.)
Build-system changes:
- libglnx and variant-schema-compiler are now Meson wrap subprojects,
not git subtrees.
Official source release tarballs include a matching version of these
subprojects.
If building from git in an environment where subprojects cannot be
downloaded automatically, please refer to Meson documentation.
Enhancements:
-
flatpak list --bytes,-blists sizes in bytes -
flatpak remote-infoandflatpak remote-ls --updatesupdate the local
AppStream cache before showing information, unless the--cachedoption
is used (#5974) -
When displaying download size estimates for apps or runtimes that use
the extra-data mechanism to download non-redistributable data out-of-band
(such as Google Chrome), include the size of the extra data in the estimate
(#5947) -
Add new API
flatpak_user_data_delete()so that app management UIs
can implement the equivalent offlatpak uninstall --delete-data
(#6728)
Bug fixes:
-
Update Meson wrap subprojects for projects that are normally taken from
the host system:- bubblewrap 0.12.0 (CVE-2026-87766)
- xdg-dbus-proxy 0.1.9 (CVE-2026-93676, CVE-2026-94422)
-
Improve hardening against symlink traversal, related to
CVE-2026-97023 and CVE-2026-97024 -
Validate GVariant structure of summaries before using generated variant
readers (#6779) -
Fix crash in system helper when iterating cache directories (#6780)
-
Avoid corrupted output from non-UTF-8 characters in error messages (#6795)
-
Fix portal passing wrong file descriptor when sandbox-expose-fd-ro
triggers fd remapping collision (#6785) -
Fix system helper tracking wrong D-Bus sender for pulls (#6781)
-
Fix extensions not being populated in the sandbox due to unhandled
EAGAIN from openat2 (#6787) -
Fix build failure with GLib versions older than 2.72 (#6775)
-
Fix alignment of columns next to a decimal column (#4917)
-
Fix subsandbox startup (
flatpak-spawn) when run from an app that
was configured with--no-talk-nameor--system-no-talk-name(#6776) -
Fix a crash when a bundle is installed with explicit key bytes (#6842)
-
Fix a crash in
flatpak document-export --noexist(#6847) -
Make
flatpak remote-add --no-follow-redirect,
flatpak remote-modify --no-follow-redirect,
flatpak remote-modify --follow-redirectwork as intended (#6844) -
Validate cursor position when emitting bash/zsh completions (#6761)
-
When listing subsets in
flatpak repo --branches, correctly de-duplicate
subsets whose names end with the name of a different subset (#6825) -
Fix the ability to pass arguments via file forwarding if the host system
uses an$XDG_RUNTIME_DIRthat is not the conventional
/run/user/$(id -u)(#6848) -
Fix compiler warnings (#6849)
-
Documentation updates (manual page fixes, code of conduct,
contributor guidelines) -
Translation updates: ka, nn, pt_BR, sl, zh_CN
Internal changes:
-
Translation updates should now be contributed through GNOME's l10n
platform, not as direct pull requests on Github. -
Add CVE IDs and reporter credits to 1.19.0's NEWS entry
-
Remove unnecessary U+200E LEFT-TO-RIGHT MARK from some older NEWS entries
1.18.4
Security fixes:
-
Prevent privileged overwrite of arbitrary files with an empty file or a
symlink to /run/host/monitor/resolv.conf when a malicious app is installed
(CVE-2026-97024, GHSA-8xgq-v545-vgvf; thanks to Sebastian Wick) -
Prevent privileged deletion of arbitrary files when a malicious app
is installed
(CVE-2026-97023, GHSA-5p67-xh8x-rq54; thanks to Sebastian Wick) -
When downloading apps or runtimes from an OCI repository that requires
authentication, don't make the authentication token visible to other users
(CVE-2026-97025, GHSA-7rvf-rqr3-43j4; thanks to AISLE in cooperation
with Red Hat) -
Restrict permissions on temporary repository directories in
/var/tmp/flatpak-cache-*
(CVE-2026-97026, GHSA-r9w3-qx54-qvc8; thanks to AISLE in cooperation
with Red Hat) -
Filter .desktop and D-Bus .service files against an allowlist of fields,
preventing denial of service and unintended interactions with host services
(CVE-2026-97027, GHSA-v64f-hrwr-j4vh; thanks to Markus Göllnitz) -
Prevent apps from sending signals to a process group that includes a
parent process outside the app, causing denial of service by killing
the desktop environment
(CVE-2026-97029, GHSA-f3p8-vr7v-gxf2; thanks to Guthrie Armstrong,
Coalition, Inc.)
Bug fixes:
-
Update Meson wrap subprojects for projects that are normally taken from
the host system:- xdg-dbus-proxy 0.1.9 (CVE-2026-93676, CVE-2026-94422)
-
Improve hardening against symlink traversal, related to
CVE-2026-97023 and CVE-2026-97024
Internal changes:
-
Add CVE IDs and reporter credits to 1.18.1's NEWS entry
-
Remove unnecessary U+200E LEFT-TO-RIGHT MARK from some older NEWS entries
1.18.3
Bug fixes:
-
Update Meson wrap subprojects for projects that are normally taken from
the host system:- bubblewrap 0.12.0 (CVE-2026-87766)
- xdg-dbus-proxy 0.1.8 (CVE-2026-93676)
-
Fix regressions in 1.18.2 when building apps/runtimes, especially on
SELinux systems or when the runtime is not installed per-user
(#6818) -
Fix subsandbox startup (
flatpak-spawn) when run from an app that
was configured with--no-talk-nameor--system-no-talk-name(#6776) -
Fix a crash when a bundle is installed with explicit key bytes (#6842)
-
Documentation updates (code of conduct, contributor guidelines)
1.18.2
Bug fixes:
-
Validate GVariant structure of summaries before using generated variant
readers (#6779) -
Fix crash in system helper when iterating cache directories (#6780)
-
Avoid corrupted output from non-UTF-8 characters in error messages (#6795)
-
Fix portal passing wrong file descriptor when sandbox-expose-fd-ro
triggers fd remapping collision (#6785) -
Fix system helper tracking wrong D-Bus sender for pulls (#6781)
-
Fix extensions not being populated in the sandbox due to unhandled
EAGAIN from openat2 (#6787) -
Fix build failure with GLib versions older than 2.72 (#6777)
1.19.0
Security fixes:
-
Fix sandbox escape with full host filesystem read/write access via symlink
attack on app data directories (GHSA-8688-9x26-hhxj) -
Fix local root privilege escalation via revokefs symlink path traversal and
commit tampering (GHSA-qrwq-7qwx-q9rp) -
Fix arbitrary root write via symlink and path traversal in extra-data
extraction (GHSA-fqx6-vh4p-42cg) -
Fix arbitrary root write via path traversal in
flatpak build-init
(GHSA-8qxj-x646-phcm) -
Fix arbitrary host file read via hardlink path traversal in OCI archive
extraction (GHSA-9rww-v4mm-x4jg) -
Fix path traversal via unvalidated architecture parameter in DeployAppstream
(GHSA-v2gw-v9h5-9q4x) -
Fix buffer overflow in OCI delta stream path names on 32-bit systems
(GHSA-jr92-2v97-wgvc) -
Fix fixed-filename writes to arbitrary locations via symlink attack on .ld.so
(GHSA-99wv-m8rp-g58x) -
Fix extension metadata path traversal allowing host filesystem probing and
unintended mount locations (GHSA-w69g-9x8j-7p8f) -
Fix anti-downgrade bypass allowing unprivileged users to downgrade system
apps (GHSA-q4gr-vc25-57m5)
Enhancements:
-
Allow system-wide downgrades through the system helper, authenticated via
new polkit actions instead of requiring root (#6669) -
Add
flatpak-coredumpctl listsubcommand and Bash completion for
flatpak-coredumpctl (#6705, #6678, #6677) -
Add flatpak_transaction_progress_get_bytes_per_second() to the library API
(#6679) -
Lock the session helper's runtime directory to prevent systemd-tmpfiles from
cleaning the p11-kit socket (#6754) -
Check OCI signatures from the mirrored repo in the system helper instead of
fetching them from the lookaside server (#6682) -
Cleanup of Bash completion (#6710)
-
Translation updates: pt_BR (#6701, #6751), sl (#6726), sv (#6750), uk
(#6715), zh_CN (#6748)
Bug fixes:
-
Fix portal flatpak-spawn environment handling regression (#6721)
-
Don't set no_interaction for --assumeyes, so that credential and polkit
prompts still work (#6744) -
Fix the inverted behavior of --clear-env (#6722)
-
Fix negated permission strings for allow and share run options (#6684, #6687)
-
Error out if file forwarding of empty paths is attempted (#6693)
-
Fix build failure when exporting metainfo releases.xml files (#6698)
-
Fix crashes in the portal update monitor (#6692) and OCI JSON handling
(#6704) -
Fix GI annotation for flatpak_instance_get_all (#6696)
-
Apply TLS certs to OCI registry requests and propagate stream write failures
to curl (#6685) -
Harden the system helper by validating remote names, dropping supplementary
groups, and not logging credentials (#6722, #6724) -
Numerous fixes for crashes, memory leaks, integer overflows, and error
handling (#6722, #6724, #6723, #6713, #6725) -
Test, CI, and documentation improvements (#6681, #6742, #6711, #6712, #6752,
#6755)
1.18.1
Security fixes:
-
Fix sandbox escape with full host filesystem read/write access via symlink
attack on app data directories (GHSA-8688-9x26-hhxj) -
Fix local root privilege escalation via revokefs symlink path traversal and
commit tampering (GHSA-qrwq-7qwx-q9rp) -
Fix arbitrary root write via symlink and path traversal in extra-data
extraction (GHSA-fqx6-vh4p-42cg) -
Fix arbitrary root write via path traversal in
flatpak build-init
(GHSA-8qxj-x646-phcm) -
Fix arbitrary host file read via hardlink path traversal in OCI archive
extraction (GHSA-9rww-v4mm-x4jg) -
Fix path traversal via unvalidated architecture parameter in DeployAppstream
(GHSA-v2gw-v9h5-9q4x) -
Fix buffer overflow in OCI delta stream path names on 32-bit systems
(GHSA-jr92-2v97-wgvc) -
Fix fixed-filename writes to arbitrary locations via symlink attack on .ld.so
(GHSA-99wv-m8rp-g58x) -
Fix extension metadata path traversal allowing host filesystem probing and
unintended mount locations (GHSA-w69g-9x8j-7p8f) -
Fix anti-downgrade bypass allowing unprivileged users to downgrade system
apps (GHSA-q4gr-vc25-57m5)
Bug fixes:
-
Fix portal flatpak-spawn environment handling regression (#6721)
-
Fix negated permission strings for allow and share run options (#6684)
-
Fix build failure when exporting metainfo releases.xml files (#6698)
-
Fix crashes in the portal update monitor (#6692) and OCI JSON handling
(#6704) -
Error out if file forwarding of empty paths is attempted (#6693)
-
Check OCI signatures from the mirrored repo in the system helper instead of
fetching from the lookaside server (#6682) -
Apply TLS certs to OCI registry requests and propagate stream write failures
to curl (#6685) -
Fix GI annotation for flatpak_instance_get_all (#6696)
-
Cleanup of Bash completion (#6710)
-
Numerous internal fixes for crashes, error handling, and hardening (#6723,
#6725)
1.18.0
Enhancements:
-
Improve error handling and printed output of
flatpak-coredumpctl(#6649,
#6680) -
Support the AMD vendor specific compute interface (
/dev/kfd) via the DRI
device permission (#6648) -
Improve the output of
flatpak updatewith failure causes (#6657) -
Improve startup time for fish shell integration (#6635)
-
Translation updates: zh_CN (#6671)
Bug fixes:
1.17.7
Enhancements:
-
Add the new permission conditionals
has-usb-deviceandhas-usb-portalto
allow apps to drop --device=all and --device=usb permissions (#6560) -
Always send the
Flatpak-Upgrade-Fromheader when updating instead of
freshly installing, to improve the quality of statistics (#6626) -
Improve how the absence of the system repo is handled (#6621)
-
Changes to repos are now more atomic which helps to avoid them being in an
invalid state. This could be observed when importing the GPG key failed,
because the system clock was wrong. (#6547) -
A function to report the age of the configuration was added to libflatpak,
which will help GNOME Software to prevent unnecessary work (#6532) -
Improve various tests (#6604, #6606, #6619, #6617, #6605, #6625)
Bug fixes:
1.17.6
Bug fixes:
-
Fix the remaining regression for Chromium based browsers by not leaking file
descriptors down to wrapped command (#6589, #6594) -
Fix a regression when installing extra-data without a runtime, which is the
case for openh264 (#6587) -
Fix the remaining regression for Epiphany by ignoring unusable sandbox-expose
paths for sub-sandboxes in the portal (#6588) -
Fix the installed tests by allowing to add a new ref to an existing temporary
ostree repo (#6592) -
Avoid closing fds 0/1/2 when they are used as a bad argument to flatpak-run,
and reduce duplication in handling file descriptor arguments (#6598)
Enhancements:
1.16.6
Bug fixes:
-
Fix the remaining regression for Chromium based browsers by not leaking file
descriptors down to wrapped command (#6589, #6594) -
Fix a regression when installing extra-data without a runtime, which is the
case for openh264 (#6587) -
Fix the remaining regression for Epiphany by ignoring unusable sandbox-expose
paths for sub-sandboxes in the portal (#6588) -
Fix the installed tests by allowing to add a new ref to an existing temporary
ostree repo (#6592) -
Avoid closing fds 0/1/2 when they are used as a bad argument to flatpak-run,
and reduce duplication in handling file descriptor arguments (#6598)
1e63e7f3fe44b602f34d92a6fe46fd8a3bc6be9460c03c2681e57976c658eec3 *flatpak-1.16.6.tar.xz