conv.

All stories
SecurityActive · 11h

Flatpak 1.19 and 1.18.1 Released with Multiple Security Fixes

New Flatpak releases patch sandbox escape, privilege escalation, and path traversal vulnerabilities.

Flatpak 1.19 and 1.18.1 Released with Multiple Security Fixes
linuxiac.com

Conversation activity · last 12 hours peak 2/15m

Peak 2 items in one 15m at Aug 11, 6 PM; 6 items over 12 hours Aug 11, 9:07 AM — no itemsAug 11, 9:22 AM — 1 item · Mastodon 1Aug 11, 9:37 AM — 1 item · Press 1Aug 11, 9:52 AM — no itemsAug 11, 10:07 AM — no itemsAug 11, 10:22 AM — no itemsAug 11, 10:37 AM — no itemsAug 11, 10:52 AM — 1 item · Mastodon 1Aug 11, 11:07 AM — no itemsAug 11, 11:22 AM — no itemsAug 11, 11:37 AM — no itemsAug 11, 11:52 AM — no itemsAug 11, 12:07 PM — no itemsAug 11, 12:22 PM — no itemsAug 11, 12:37 PM — no itemsAug 11, 12:52 PM — no itemsAug 11, 1:07 PM — no itemsAug 11, 1:22 PM — no itemsAug 11, 1:37 PM — 1 item · Hacker News 1Aug 11, 1:52 PM — no itemsAug 11, 2:07 PM — no itemsAug 11, 2:22 PM — no itemsAug 11, 2:37 PM — no itemsAug 11, 2:52 PM — no itemsAug 11, 3:07 PM — no itemsAug 11, 3:22 PM — no itemsAug 11, 3:37 PM — no itemsAug 11, 3:52 PM — no itemsAug 11, 4:07 PM — no itemsAug 11, 4:22 PM — no itemsAug 11, 4:37 PM — no itemsAug 11, 4:52 PM — no itemsAug 11, 5:07 PM — no itemsAug 11, 5:22 PM — no itemsAug 11, 5:37 PM — no itemsAug 11, 5:52 PM — no itemsAug 11, 6:07 PM — no itemsAug 11, 6:22 PM — no itemsAug 11, 6:37 PM — 2 items · Mastodon 2Aug 11, 6:52 PM — no itemsAug 11, 7:07 PM — no itemsAug 11, 7:22 PM — no itemsAug 11, 7:37 PM — no itemsAug 11, 7:52 PM — no itemsAug 11, 8:07 PM — no itemsAug 11, 8:22 PM — no itemsAug 11, 8:37 PM — no itemsAug 11, 8:52 PM — no items 2 items · 6:37 PM
10 AM12 PM2 PM4 PM6 PMnow · 9:07 PM

Summary, timeline and people extracted by Claude from 6 items across 3 sources · 2h ago. Quotes are verbatim.

Flatpak, the Linux application sandboxing framework, released version 1.19 (development) and 1.18.1 (stable) on August 11, 2026, addressing nine security vulnerabilities. The fixes include critical issues such as sandbox escape enabling full read/write access to host filesystems, local root privilege escalation via symlink attacks, and path traversal flaws in OCI handling and extra-data extraction.

  • Critical sandbox escape vulnerability allowed apps to read and write anywhere on the host filesystem.
  • Local root privilege escalation via symlink path traversal in revokefs and OCI archive extraction affected both development and stable releases.
  • Nine security fixes span sandbox isolation, filesystem access, privilege boundaries, OCI handling, and downgrade protection.
  • Users are urged to update to Flatpak 1.18.1 or later, especially those running desktop tools and AI applications.

How it unfolded

  1. Mastodon users sayzard and governa share the Flatpak release news; sayzard emphasizes the urgency for Linux environments running desktop tools and AI applications to update to 1.18.1 or later.

    “Flatpak을 통해 데스크톱 도구나 AI 개발 애플리케이션을 배포·실행하는 Linux 환경은 영향을 확인하고 1.18.1 이상으로 신속히 업데이트해야 한다.”

    sayzard · Mastodon ↗
  2. Linuxiac publishes detailed breakdown of vulnerabilities fixed: sandbox escape allowing full filesystem access, local root privilege escalation via revokefs symlink path traversal, arbitrary file writes, OCI hardlink path traversal, buffer overflow in 32-bit systems, and downgrade protection bypass.

    “The most critical fix in this release stops a sandbox escape that could let an app read and write anywhere on the host filesystem.”

    Linuxiac · Mastodon ↗
  3. Michael Larabel reports that both Flatpak 1.19 (development) and 1.18.1 (stable) were released with multiple newly-discovered security issues.

  4. 9to5linux reports the release of Flatpak 1.18.1 with bug and security fixes for the Linux app sandboxing framework.

What people are saying verbatim

“The most critical fix in this release stops a sandbox escape that could let an app read and write anywhere on the host filesystem.”

Linuxiac, Linux news outlet · Linuxiac ↗

“Another key fix stops a local root privilege escalation caused by symlink path traversal in revokefs and commit tampering.”

Linuxiac, Linux news outlet · Linuxiac ↗

“Flatpak을 통해 데스크톱 도구나 AI 개발 애플리케이션을 배포·실행하는 Linux 환경은 영향을 확인하고 1.18.1 이상으로 신속히 업데이트해야 한다.”

sayzard, Mastodon user · Mastodon ↗ · Aug 11, 6:43 PM

“Flatpak 1.18.1 also improves downgrade protection by closing a loophole that let unprivileged users bypass safeguards and downgrade installed apps.”

Linuxiac, Linux news outlet · Linuxiac ↗

“They also fixed a buffer overflow in OCI delta stream path names on 32-bit systems.”

Linuxiac, Linux news outlet · Linuxiac ↗

Voices from the web unedited

  • # Flatpak 1.18.1 # Linux App Sandboxing and Distribution Framework Released with Bug and Security Fixes https:// 9to5linux.com/flatpak-1-18-1-l inux-app-sandboxing-framework-brings-bug-and-security-fixes @ FlatpakApps # OpenSource # FreeSoftware

    9to5linux@floss.socialMastodon · fosstodon.org11h ago5▲view on Mastodon ↗
  • Flatpak 1.18.1 is out with security fixes addressing a sandbox escape, local root privilege escalation, path traversal issues, and arbitrary file writes. https:// linuxiac.com/flatpak-1-18-1-fi xes-sandbox-escape-and-root-privilege-escalation-flaws/ # linux # opensource # flatpak

    linuxiac@mastodon.socialMastodon · newsie.social10h agoview on Mastodon ↗