flatpak 1.10.5-0+deb11u1 source package in Debian

Changelog

flatpak (1.10.5-0+deb11u1) bullseye-security; urgency=medium

  * New upstream stable release 1.10.4
    - Don't allow VFS manipulation which could be used to trick portals
      into allowing unintended access to host
      (Closes: #995935, CVE-2021-41133, GHSA-67h7-w3jq-vh4q)
    - Fix parental controls check when installing system-wide as non-root
    - OCI now uses the pax tar format, which handles large files better
      than GNU tar
    - tests: Fix test-sideload.sh if ostree is built with curl backend
      (this change is unnecessary but harmless in the configuration used
      in Debian)
  * New upstream stable release 1.10.5
    - Fix regressions in 1.12.0 with extra data or --allow=multiarch.
      This only partially prevents use of VFS-manipulating syscalls if a
      newer kernel is used with an older libseccomp, but that's the best
      we will be able to achieve without new features in libseccomp and/or
      bubblewrap.
  * d/control: Build-depend on libseccomp 2.5.0.
    This ensures that we can block creation of new user namespaces via
    clone3(), which should be enough to prevent CVE-2021-41133 on
    at least Debian 11 kernels (Linux 5.10). It also allows blocking most
    of the syscalls we want to block; we cannot guarantee to be able to
    block mount_setattr(), which was only added in libseccomp 2.5.2, but
    that syscall was new in Linux 5.12.
  * d/p/Fix-handling-of-syscalls-only-allowed-by-devel.patch:
    Fix error handling for syscalls that are only allowed with --devel

 -- Simon McVittie <email address hidden>  Sun, 10 Oct 2021 14:14:51 +0100

Upload details

Uploaded by:
Utopia Maintenance Team
Uploaded to:
Bullseye
Original maintainer:
Utopia Maintenance Team
Architectures:
linux-any all
Section:
misc
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Downloads

File Size SHA-256 Checksum
flatpak_1.10.5-0+deb11u1.dsc 3.5 KiB b6c0d181992d5f9abfe310a1d42a671dde6fe6ceedc04dbb5e9ff957f018d949
flatpak_1.10.5.orig.tar.xz 1.4 MiB 3ac884b99063cc78e65de94fe015b4146624f3ab8b9f2f84e4017d508af4223b
flatpak_1.10.5-0+deb11u1.debian.tar.xz 31.5 KiB 6d9e3024a986d6ed947046b55e4772da17d6fc084bc0093c27f47cb947e4d6b7

No changes file available.

Binary packages built by this source