TEMP-1136299-DD6181

NameTEMP-1136299-DD6181
Descriptionyelp: Sandbox escape
SourceAutomatically generated temporary name. Not for external reference.
Debian Bugs1136299

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
yelp (PTS)bullseye3.38.3-1vulnerable
bullseye (security)3.38.3-1+deb11u1vulnerable
bookworm, bookworm (security)42.2-1+deb12u1vulnerable
trixie42.2-4vulnerable
forky, sid49.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
yelpsource(unstable)49.1-11136299

Notes

https://blogs.gnome.org/mcatanzaro/2026/05/11/flatpak-sandbox-escape-via-yelp/
https://gitlab.gnome.org/GNOME/yelp/-/work_items/238
Fixed by: https://gitlab.gnome.org/GNOME/yelp/-/commit/d220aa2f754eed4e6a006a4acaa68b31892dea2b (49.1)
Fixed by: https://gitlab.gnome.org/GNOME/yelp/-/commit/c8c8244c8a812860782d635890c9b6c43ecc2639 (49.1)

Search for package or bug name: Reporting problems