Flatpak 1.18.4 Released With Important Security Fixes

Written by Michael Larabel in Desktop on 28 September 2026 at 09:20 AM EDT. 24 Comments
DESKTOP
Flatpak 1.18.4 is out today with a number of high profile security fixes for this app sandboxing and distribution tech.

Flatpak 1.18.4 fixes a security issue to prevent privileged overwrite of arbitrary files with an empty file or a symlink to /run/host/monitor/resolv.conf by malicious apps. There is also another security issue addressed to prevent the privileged deletion of arbitrary files by malicious apps.

There is also a fix when downloading apps or runtimes from an OCI repository with authentication that the authentication tokens would be visible to other users.

Flatpak logo


Flatpak 1.18.4 is also now filtering .desktop and D-Bus .service files against an allow-list of fields to prevent potential denial of service and unintended interactions with host services. Another denial of service addressed is to prevent apps from sending signals to a process group that includes parent processes outside the app, which could cause a denial of service by killing the desktop environment.

These plus other security fixes are all now bundled up in Flatpak 1.18.4. Also out today is Flatpak 1.19.2 as the newest development version with these security fixes added.
Related News
About The Author

Michael Larabel is the principal author of Phoronix.com and founded the site in 2004 with a focus on enriching the Linux hardware experience. Michael has written more than 20,000 articles covering the state of Linux hardware support, Linux performance, graphics drivers, and other topics. Michael is also the lead developer of the Phoronix Test Suite, Phoromatic, and OpenBenchmarking.org automated benchmarking software. He can be followed via Twitter, LinkedIn, or contacted via MichaelLarabel.com.

Popular News This Week