Flatpak 1.18.4 Released With Important Security Fixes

Flatpak 1.18.4 fixes a security issue to prevent privileged overwrite of arbitrary files with an empty file or a symlink to /run/host/monitor/resolv.conf by malicious apps. There is also another security issue addressed to prevent the privileged deletion of arbitrary files by malicious apps.
There is also a fix when downloading apps or runtimes from an OCI repository with authentication that the authentication tokens would be visible to other users.
Flatpak 1.18.4 is also now filtering .desktop and D-Bus .service files against an allow-list of fields to prevent potential denial of service and unintended interactions with host services. Another denial of service addressed is to prevent apps from sending signals to a process group that includes parent processes outside the app, which could cause a denial of service by killing the desktop environment.
These plus other security fixes are all now bundled up in Flatpak 1.18.4. Also out today is Flatpak 1.19.2 as the newest development version with these security fixes added.
24 Comments
