| Release | Version |
|---|---|
| bullseye | 1.10.8-0+deb11u2 |
| bullseye (security) | 1.10.8-0+deb11u3 |
| bookworm | 1.14.10-1~deb12u1 |
| trixie | 1.16.3-1~deb13u1 |
| trixie (security) | 1.16.6-1~deb13u1 |
| forky | 1.16.6-1 |
| sid | 1.16.6-1 |
| Bug | bullseye | bookworm | trixie | forky | sid | Description |
|---|---|---|---|---|---|---|
| TEMP-1132946-5EDD2C | vulnerable | vulnerable | fixed | fixed | fixed | GHSA-2fxp-43j9-pwvc: Arbitrary read-access to files readable by _flatpak user |
| TEMP-1132945-4CEFB2 | vulnerable | vulnerable | fixed | fixed | fixed | GHSA-89xm-3m96-w3jg: cross-user CancelPull orphans another user's ongoing pull |
| CVE-2026-34079 | vulnerable | vulnerable | fixed | fixed | fixed | Flatpak is a Linux application sandboxing and distribution framework. ... |
| CVE-2026-34078 | vulnerable | vulnerable | fixed | fixed | fixed | Flatpak is a Linux application sandboxing and distribution framework. ... |
| Bug | Description |
|---|---|
| CVE-2024-42472 | Flatpak is a Linux application sandboxing and distribution framework. ... |
| CVE-2024-32462 | Flatpak is a system for building, distributing, and running sandboxed ... |
| CVE-2023-28101 | Flatpak is a system for building, distributing, and running sandboxed ... |
| CVE-2023-28100 | Flatpak is a system for building, distributing, and running sandboxed ... |
| CVE-2022-21682 | Flatpak is a Linux application sandboxing and distribution framework. ... |
| CVE-2021-43860 | Flatpak is a Linux application sandboxing and distribution framework. ... |
| CVE-2021-41133 | Flatpak is a system for building, distributing, and running sandboxed ... |
| CVE-2021-21381 | Flatpak is a system for building, distributing, and running sandboxed ... |
| CVE-2021-21261 | Flatpak is a system for building, distributing, and running sandboxed ... |
| CVE-2019-10063 | Flatpak before 1.0.8, 1.1.x and 1.2.x before 1.2.4, and 1.3.x before 1 ... |
| CVE-2019-8308 | Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc ... |
| CVE-2018-6560 | In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0 ... |
| CVE-2017-9780 | In Flatpak before 0.8.7, a third-party app repository could include ma ... |
| DSA / DLA | Description |
|---|---|
| DSA-6207-1 | flatpak - security update |
| DLA-4099-1 | flatpak - security update |
| DSA-5749-1 | flatpak - security update |
| DSA-5666-1 | flatpak - security update |
| DSA-5049-1 | flatpak - security update |
| DSA-4984-1 | flatpak - security update |
| DSA-4868-1 | flatpak - security update |
| DSA-4830-2 | flatpak - regression update |
| DSA-4830-1 | flatpak - security update |
| DSA-4390-1 | flatpak - security update |
| DSA-3895-1 | flatpak - security update |