Version in base suite: 1.16.6-1~deb13u2 Base version: flatpak_1.16.6-1~deb13u2 Target version: flatpak_1.16.6-1~deb13u3 Base file: /srv/ftp-master.debian.org/ftp/pool/main/f/flatpak/flatpak_1.16.6-1~deb13u2.dsc Target file: /srv/ftp-master.debian.org/policy/pool/main/f/flatpak/flatpak_1.16.6-1~deb13u3.dsc changelog | 28 patches/CVE-2026-97023-97024/dir-Add-fd-relative-helpers-for-accessing-deploy-director.patch | 151 +++ patches/CVE-2026-97023-97024/dir-Reuse-app_files_dfd-for-.ref-write-during-deploy.patch | 47 + patches/CVE-2026-97023-97024/dir-Use-deploy-helpers-in-apply_extra_data-and-flatpak_di.patch | 153 +++ patches/CVE-2026-97023-97024/dir-Use-fd-relative-operations-for-app-export-during-depl.patch | 140 +++ patches/CVE-2026-97023-97024/dir-Use-fd-relative-operations-for-export-bin-removal-dur.patch | 80 ++ patches/CVE-2026-97023-97024/dir-Use-fd-relative-operations-for-files-etc-during-runti.patch | 122 +++ patches/CVE-2026-97023-97024/dir-Use-fd-relative-operations-in-deploy_dir_is_locked.patch | 95 ++ patches/CVE-2026-97023-97024/run-Use-deploy-helper-to-open-runtime-files-directory.patch | 60 + patches/CVE-2026-97025/oci-Stop-persisting-bearer-token-to-child-repo-on-disk.patch | 63 + patches/CVE-2026-97026/common-Restrict-tmpdir-permissions-from-0777-to-0755.patch | 34 patches/CVE-2026-97027/dir-Validate-Desktop-Entry-and-D-Bus-Service.patch | 399 ++++++++++ patches/CVE-2026-97029/common-Put-each-bubblewrap-child-process-in-its-own-proce.patch | 34 patches/series | 12 14 files changed, 1416 insertions(+), 2 deletions(-) dpkg-source: warning: cannot verify inline signature for /srv/release.debian.org/tmp/tmpz_9uyy74/flatpak_1.16.6-1~deb13u2.dsc: no acceptable signature found dpkg-source: warning: cannot verify inline signature for /srv/release.debian.org/tmp/tmpz_9uyy74/flatpak_1.16.6-1~deb13u3.dsc: no acceptable signature found diff -Nru flatpak-1.16.6/debian/changelog flatpak-1.16.6/debian/changelog --- flatpak-1.16.6/debian/changelog 2026-08-11 13:03:38.000000000 +0000 +++ flatpak-1.16.6/debian/changelog 2026-09-28 13:13:01.000000000 +0000 @@ -1,3 +1,27 @@ +flatpak (1.16.6-1~deb13u3) trixie-security; urgency=high + + * d/patches: Backport security fixes from 1.18.4 (Closes: #1149218): + - Fix two related symlink traversal vulnerabilities to prevent arbitrary + file deletion and limited file overwriting outside the deploy + directory, and harden related code paths against symlink traversal + (deletion: CVE-2026-97023, GHSA-5p67-xh8x-rq54) + (overwriting: CVE-2026-97024, GHSA-8xgq-v545-vgvf) + - When using OCI remotes, don't make authentication token readable by + other users + (CVE-2026-97025, GHSA-7rvf-rqr3-43j4) + - Restrict permissions of temporary directories /var/tmp/flatpak-cache-* + (CVE-2026-97026, GHSA-r9w3-qx54-qvc8) + - Filter D-Bus .service files and freedesktop.org .desktop files + with an allowlist to prevent denial of service and possibly + sandbox escape + (CVE-2026-97027, GHSA-v64f-hrwr-j4vh) + - Prevent sandboxed processes from killing a parent process outside the + sandbox + (CVE-2026-97029, GHSA-f3p8-vr7v-gxf2) + * Mention CVE-2026-90616, CVE-2026-92162 in previous changelog entry + + -- Simon McVittie Mon, 28 Sep 2026 14:13:01 +0100 + flatpak (1.16.6-1~deb13u2) trixie-security; urgency=high * d/patches: Backport security fixes from 1.18.1 (Closes: #1144130) @@ -23,7 +47,7 @@ - d/p/GHSA-8688-9x26-hhxj/*.patch: Fix a sandbox escape involving directories inside ~/.var/app/APP_ID. A malicious or compromised Flatpak app could write to arbitrary files - outside its sandbox. + outside its sandbox. (CVE-2026-90616) - d/p/GHSA-99wv-m8rp-g58x/*.patch: Fix a sandbox escape involving the ld.so cache. A malicious or compromised Flatpak app could write files with a fixed @@ -32,7 +56,7 @@ Fix local privilege escalation involving crafted OCI architecture names. A malicious local user on a system with an OCI remote configured (unusual on non-Fedora systems) could trick the flatpak-system-helper - process into writing outside /var/lib/flatpak. + process into writing outside /var/lib/flatpak. (CVE-2026-92162) - d/p/GHSA-w69g-9x8j-7p8f/*.patch: Fix reading outside sandbox involving crafted extension metadata. A malicious or compromised Flatpak app could find out whether specific diff -Nru flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/dir-Add-fd-relative-helpers-for-accessing-deploy-director.patch flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/dir-Add-fd-relative-helpers-for-accessing-deploy-director.patch --- flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/dir-Add-fd-relative-helpers-for-accessing-deploy-director.patch 1970-01-01 00:00:00.000000000 +0000 +++ flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/dir-Add-fd-relative-helpers-for-accessing-deploy-director.patch 2026-09-28 13:13:01.000000000 +0000 @@ -0,0 +1,151 @@ +From: Sebastian Wick +Date: Tue, 18 Aug 2026 19:05:54 +0200 +Subject: dir: Add fd-relative helpers for accessing deploy directories + +Add deploy_open_fd, flatpak_deploy_get_files_fd, +flatpak_deploy_get_export_fd, and flatpak_deploy_get_metadata_fd which +open files within a deploy directory using fd-relative operations with +symlink protection. + +deploy_open_fd uses a two-step resolution: +GLNX_CHASE_RESOLVE_NO_SYMLINKS at the directory boundary (files/, +export/) to reject symlinks, then GLNX_CHASE_RESOLVE_BENEATH within the +directory to safely resolve symlinks relative to the directory root. + +These will be used by subsequent commits to close TOCTOU gaps where +GFile path operations were used after fd-based validation. + +Prerequsite for fixing CVE-2026-97023, CVE-2026-97024 + +Helps: https://github.com/flatpak/flatpak/security/advisories/GHSA-5p67-xh8x-rq54 +Helps: https://github.com/flatpak/flatpak/security/advisories/GHSA-8xgq-v545-vgvf +--- + common/flatpak-dir-private.h | 12 ++++++ + common/flatpak-dir.c | 91 ++++++++++++++++++++++++++++++++++++++++++++ + 2 files changed, 103 insertions(+) + +diff --git a/common/flatpak-dir-private.h b/common/flatpak-dir-private.h +index 50793b2..361e295 100644 +--- a/common/flatpak-dir-private.h ++++ b/common/flatpak-dir-private.h +@@ -402,6 +402,18 @@ GFile * flatpak_deploy_get_files (FlatpakDeploy *deploy); + FlatpakContext *flatpak_deploy_get_overrides (FlatpakDeploy *deploy); + GKeyFile * flatpak_deploy_get_metadata (FlatpakDeploy *deploy); + ++int flatpak_deploy_get_files_fd (int deploy_dfd, ++ const char *subpath, ++ GlnxChaseFlags flags, ++ GError **error); ++int flatpak_deploy_get_export_fd (int deploy_dfd, ++ const char *subpath, ++ GlnxChaseFlags flags, ++ GError **error); ++int flatpak_deploy_get_metadata_fd (int deploy_dfd, ++ int access_flags, ++ GError **error); ++ + FlatpakDir * flatpak_dir_new (GFile *basedir, + gboolean user); + FlatpakDir * flatpak_dir_clone (FlatpakDir *self); +diff --git a/common/flatpak-dir.c b/common/flatpak-dir.c +index ad4def3..1380a8a 100644 +--- a/common/flatpak-dir.c ++++ b/common/flatpak-dir.c +@@ -8592,6 +8592,97 @@ extract_extra_data (FlatpakDir *self, + return TRUE; + } + ++static int ++deploy_open_fd (int deploy_dfd, ++ const char *name, ++ const char *subpath, ++ GlnxChaseFlags flags, ++ GError **error) ++{ ++ glnx_autofd int dfd = -1; ++ glnx_autofd int fd = -1; ++ ++ g_return_val_if_fail ((flags & ~(GLNX_CHASE_MUST_BE_DIRECTORY | ++ GLNX_CHASE_MUST_BE_REGULAR)) == 0, -1); ++ ++ if (subpath == NULL) ++ { ++ fd = glnx_chaseat (deploy_dfd, name, ++ GLNX_CHASE_RESOLVE_NO_SYMLINKS | flags, ++ error); ++ if (fd < 0) ++ g_prefix_error (error, _("Failed to open %s: "), name); ++ ++ return g_steal_fd (&fd); ++ } ++ ++ dfd = glnx_chaseat (deploy_dfd, name, ++ GLNX_CHASE_RESOLVE_NO_SYMLINKS | ++ GLNX_CHASE_MUST_BE_DIRECTORY, ++ error); ++ if (dfd < 0) ++ { ++ g_prefix_error (error, _("Failed to open %s: "), name); ++ return -1; ++ } ++ ++ /* We cannot use RESOLVE_IN_ROOT because files gets mounted either in ++ * /app or /usr in the real filesystem, making resolution incorrect. ++ * Using RESOLVE_BENEATH gives us support for most symlink setups. */ ++ fd = glnx_chaseat (dfd, subpath, ++ GLNX_CHASE_RESOLVE_BENEATH | flags, ++ error); ++ if (fd < 0) ++ g_prefix_error (error, _("Failed to open %s/%s: "), name, subpath); ++ ++ return g_steal_fd (&fd); ++} ++ ++int ++flatpak_deploy_get_files_fd (int deploy_dfd, ++ const char *subpath, ++ GlnxChaseFlags flags, ++ GError **error) ++{ ++ return deploy_open_fd (deploy_dfd, "files", subpath, flags, error); ++} ++ ++int ++flatpak_deploy_get_export_fd (int deploy_dfd, ++ const char *subpath, ++ GlnxChaseFlags flags, ++ GError **error) ++{ ++ return deploy_open_fd (deploy_dfd, "export", subpath, flags, error); ++} ++ ++int ++flatpak_deploy_get_metadata_fd (int deploy_dfd, ++ int access_flags, ++ GError **error) ++{ ++ glnx_autofd int path_fd = -1; ++ glnx_autofd int fd = -1; ++ ++ g_return_val_if_fail ((access_flags & ~(O_RDONLY | O_RDWR)) == 0, -1); ++ ++ path_fd = glnx_chaseat (deploy_dfd, "metadata", ++ GLNX_CHASE_RESOLVE_NO_SYMLINKS | ++ GLNX_CHASE_MUST_BE_REGULAR, ++ error); ++ if (path_fd < 0) ++ { ++ g_prefix_error (error, _("Failed to open metadata: ")); ++ return -1; ++ } ++ ++ fd = glnx_fd_reopen (path_fd, access_flags, error); ++ if (fd < 0) ++ g_prefix_error (error, _("Failed to open metadata: ")); ++ ++ return g_steal_fd (&fd); ++} ++ + static gboolean + apply_extra_data (FlatpakDir *self, + int checkoutdir_dfd, diff -Nru flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/dir-Reuse-app_files_dfd-for-.ref-write-during-deploy.patch flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/dir-Reuse-app_files_dfd-for-.ref-write-during-deploy.patch --- flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/dir-Reuse-app_files_dfd-for-.ref-write-during-deploy.patch 1970-01-01 00:00:00.000000000 +0000 +++ flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/dir-Reuse-app_files_dfd-for-.ref-write-during-deploy.patch 2026-09-28 13:13:01.000000000 +0000 @@ -0,0 +1,47 @@ +From: Sebastian Wick +Date: Tue, 18 Aug 2026 20:36:32 +0200 +Subject: dir: Reuse app_files_dfd for .ref write during deploy + +The previous code built a path from checkoutdir_basename + "files" and +opened it via glnx_opendirat(deploy_base_dfd, ...). Since O_NOFOLLOW +only applies to the last path component, a symlink at the intermediate +checkoutdir_basename component would be followed. Reuse the +already-open app_files_dfd instead. + +Hardening related to CVE-2026-97023, CVE-2026-97024 + +Helps: https://github.com/flatpak/flatpak/security/advisories/GHSA-5p67-xh8x-rq54 +Helps: https://github.com/flatpak/flatpak/security/advisories/GHSA-8xgq-v545-vgvf +--- + common/flatpak-dir.c | 18 +++++------------- + 1 file changed, 5 insertions(+), 13 deletions(-) + +diff --git a/common/flatpak-dir.c b/common/flatpak-dir.c +index 3a04aed..70cdaa9 100644 +--- a/common/flatpak-dir.c ++++ b/common/flatpak-dir.c +@@ -9376,19 +9376,11 @@ flatpak_dir_deploy (FlatpakDir *self, + metadata_contents, metadata_size, error)) + return FALSE; + +- { +- g_autofree char *files_path = g_build_filename (checkoutdir_basename, "files", NULL); +- glnx_autofd int files_dfd = -1; +- +- if (!glnx_opendirat (deploy_base_dfd, files_path, FALSE, &files_dfd, error)) +- return FALSE; +- +- if (!glnx_file_replace_contents_at (files_dfd, ".ref", +- (const guint8 *) "", 0, +- GLNX_FILE_REPLACE_NODATASYNC, +- cancellable, error)) +- return FALSE; +- } ++ if (!glnx_file_replace_contents_at (app_files_dfd, ".ref", ++ (const guint8 *) "", 0, ++ GLNX_FILE_REPLACE_NODATASYNC, ++ cancellable, error)) ++ return FALSE; + + /* Never export any binaries bundled with the app */ + { diff -Nru flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/dir-Use-deploy-helpers-in-apply_extra_data-and-flatpak_di.patch flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/dir-Use-deploy-helpers-in-apply_extra_data-and-flatpak_di.patch --- flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/dir-Use-deploy-helpers-in-apply_extra_data-and-flatpak_di.patch 1970-01-01 00:00:00.000000000 +0000 +++ flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/dir-Use-deploy-helpers-in-apply_extra_data-and-flatpak_di.patch 2026-09-28 13:13:01.000000000 +0000 @@ -0,0 +1,153 @@ +From: Sebastian Wick +Date: Tue, 18 Aug 2026 20:38:29 +0200 +Subject: dir: Use deploy helpers in apply_extra_data and flatpak_dir_deploy + +Convert remaining call sites to use flatpak_deploy_get_files_fd and +flatpak_deploy_get_metadata_fd. + +In flatpak_dir_deploy, metadata was read via GFile with no symlink +protection and all errors silently ignored. Use the metadata helper +which rejects symlinks and only tolerates ENOENT. + +Hardening related to CVE-2026-97023, CVE-2026-97024 + +Helps: https://github.com/flatpak/flatpak/security/advisories/GHSA-5p67-xh8x-rq54 +Helps: https://github.com/flatpak/flatpak/security/advisories/GHSA-8xgq-v545-vgvf +--- + common/flatpak-dir.c | 73 ++++++++++++++++++++++++++++------------------------ + 1 file changed, 40 insertions(+), 33 deletions(-) + +diff --git a/common/flatpak-dir.c b/common/flatpak-dir.c +index 70cdaa9..b9e95e6 100644 +--- a/common/flatpak-dir.c ++++ b/common/flatpak-dir.c +@@ -8682,8 +8682,7 @@ apply_extra_data (FlatpakDir *self, + g_auto(GStrv) minimal_envp = NULL; + g_autofree char *runtime_arch = NULL; + glnx_autofd int app_files_dfd = -1; +- glnx_autofd int metadata_path_fd = -1; +- glnx_autofd int metadata_read_fd = -1; ++ glnx_autofd int metadata_fd = -1; + glnx_autofd int extra_dfd = -1; + glnx_autofd int usr_fd = -1; + int exit_status; +@@ -8691,20 +8690,17 @@ apply_extra_data (FlatpakDir *self, + g_autoptr(GError) local_error = NULL; + FlatpakRunFlags run_flags; + +- app_files_dfd = glnx_chaseat (checkoutdir_dfd, "files", +- GLNX_CHASE_RESOLVE_NO_SYMLINKS | +- GLNX_CHASE_MUST_BE_DIRECTORY, +- error); ++ app_files_dfd = flatpak_deploy_get_files_fd (checkoutdir_dfd, NULL, 0, error); + if (app_files_dfd < 0) + return FALSE; + + { + glnx_autofd int apply_extra_fd = -1; + +- apply_extra_fd = glnx_chaseat (app_files_dfd, "bin/apply_extra", +- GLNX_CHASE_RESOLVE_BENEATH | +- GLNX_CHASE_MUST_BE_REGULAR, +- &local_error); ++ apply_extra_fd = flatpak_deploy_get_files_fd (checkoutdir_dfd, ++ "bin/apply_extra", ++ GLNX_CHASE_MUST_BE_REGULAR, ++ &local_error); + if (apply_extra_fd < 0) + { + if (g_error_matches (local_error, G_IO_ERROR, G_IO_ERROR_NOT_FOUND)) +@@ -8717,18 +8713,11 @@ apply_extra_data (FlatpakDir *self, + } + } + +- metadata_path_fd = glnx_chaseat (checkoutdir_dfd, "metadata", +- GLNX_CHASE_RESOLVE_NO_SYMLINKS | +- GLNX_CHASE_MUST_BE_REGULAR, +- error); +- if (metadata_path_fd < 0) +- return FALSE; +- +- metadata_read_fd = glnx_fd_reopen (metadata_path_fd, O_RDONLY, error); +- if (metadata_read_fd < 0) ++ metadata_fd = flatpak_deploy_get_metadata_fd (checkoutdir_dfd, O_RDONLY, error); ++ if (metadata_fd < 0) + return FALSE; + +- metadata_contents = glnx_fd_readall_utf8 (metadata_read_fd, &metadata_size, ++ metadata_contents = glnx_fd_readall_utf8 (metadata_fd, &metadata_size, + cancellable, error); + if (metadata_contents == NULL) + return FALSE; +@@ -8783,10 +8772,9 @@ apply_extra_data (FlatpakDir *self, + runtime_files = flatpak_deploy_get_files (runtime_deploy); + } + +- extra_dfd = glnx_chaseat (app_files_dfd, "extra", +- GLNX_CHASE_RESOLVE_BENEATH | +- GLNX_CHASE_MUST_BE_DIRECTORY, +- error); ++ extra_dfd = flatpak_deploy_get_files_fd (checkoutdir_dfd, "extra", ++ GLNX_CHASE_MUST_BE_DIRECTORY, ++ error); + if (extra_dfd < 0) + return FALSE; + +@@ -9125,7 +9113,6 @@ flatpak_dir_deploy (FlatpakDir *self, + gboolean created_extra_data = FALSE; + g_autoptr(GVariant) commit_metadata = NULL; + g_auto(GLnxLockFile) lock = { 0, }; +- g_autoptr(GFile) metadata_file = NULL; + g_autofree char *metadata_contents = NULL; + gsize metadata_size = 0; + const char *flatpak; +@@ -9280,10 +9267,7 @@ flatpak_dir_deploy (FlatpakDir *self, + return FALSE; + + /* Extract any extra data */ +- app_files_dfd = glnx_chaseat (checkoutdir_dfd, "files", +- GLNX_CHASE_RESOLVE_NO_SYMLINKS | +- GLNX_CHASE_MUST_BE_DIRECTORY, +- error); ++ app_files_dfd = flatpak_deploy_get_files_fd (checkoutdir_dfd, NULL, 0, error); + if (app_files_dfd < 0) + return FALSE; + +@@ -9353,10 +9337,33 @@ flatpak_dir_deploy (FlatpakDir *self, + } + + keyfile = g_key_file_new (); +- metadata_file = g_file_resolve_relative_path (checkoutdir, "metadata"); +- if (g_file_load_contents (metadata_file, NULL, +- &metadata_contents, +- &metadata_size, NULL, NULL)) ++ ++ { ++ g_autoptr(GError) local_error = NULL; ++ glnx_autofd int metadata_fd = -1; ++ ++ metadata_fd = flatpak_deploy_get_metadata_fd (checkoutdir_dfd, O_RDONLY, &local_error); ++ if (metadata_fd < 0 && ++ !g_error_matches (local_error, G_IO_ERROR, G_IO_ERROR_NOT_FOUND)) ++ { ++ g_propagate_error (error, g_steal_pointer (&local_error)); ++ return FALSE; ++ } ++ ++ if (metadata_fd >= 0) ++ { ++ g_autoptr(GBytes) bytes = NULL; ++ ++ bytes = glnx_fd_readall_bytes (metadata_fd, cancellable, error); ++ if (bytes == NULL) ++ return FALSE; ++ ++ metadata_contents = g_bytes_unref_to_data (g_steal_pointer (&bytes), ++ &metadata_size); ++ } ++ } ++ ++ if (metadata_contents != NULL) + { + if (!g_key_file_load_from_data (keyfile, + metadata_contents, diff -Nru flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/dir-Use-fd-relative-operations-for-app-export-during-depl.patch flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/dir-Use-fd-relative-operations-for-app-export-during-depl.patch --- flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/dir-Use-fd-relative-operations-for-app-export-during-depl.patch 1970-01-01 00:00:00.000000000 +0000 +++ flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/dir-Use-fd-relative-operations-for-app-export-during-depl.patch 2026-09-28 13:13:01.000000000 +0000 @@ -0,0 +1,140 @@ +From: Sebastian Wick +Date: Tue, 11 Aug 2026 23:21:48 +0200 +Subject: dir: Use fd-relative operations for app export during deploy + +The app branch in flatpak_dir_deploy() used GFile operations to +create directories and write wrapper scripts under the export +directory. While the export symlink is already rejected by the +common-path bin removal, convert the app branch to fd-relative +operations as defense-in-depth. + +Use fd-relative operations in export_dir and flatpak_rewrite_export_dir +to reject symlinks. + +Hardening related to CVE-2026-97023, CVE-2026-97024 + +Helps: https://github.com/flatpak/flatpak/security/advisories/GHSA-5p67-xh8x-rq54 +Helps: https://github.com/flatpak/flatpak/security/advisories/GHSA-8xgq-v545-vgvf +--- + common/flatpak-dir.c | 59 +++++++++++++++++++++------------------------------- + 1 file changed, 24 insertions(+), 35 deletions(-) + +diff --git a/common/flatpak-dir.c b/common/flatpak-dir.c +index 60ea56f..4b3595b 100644 +--- a/common/flatpak-dir.c ++++ b/common/flatpak-dir.c +@@ -8215,41 +8215,21 @@ flatpak_rewrite_export_dir (const char *app, + const char *arch, + GKeyFile *metadata, + const char * const *previous_ids, +- GFile *source, ++ int export_dfd, + GCancellable *cancellable, + GError **error) + { +- gboolean ret = FALSE; +- g_autoptr(GFile) parent = g_file_get_parent (source); +- glnx_autofd int parentfd = -1; +- g_autofree char *name = g_file_get_basename (source); +- +- /* Start with a source path of "" - we don't care about +- * the "export" component and we want to start path traversal +- * relative to it. */ +- const char *source_path = ""; + g_autoptr(FlatpakContext) context = flatpak_context_new (); + + if (!flatpak_context_load_metadata (context, metadata, error)) + return FALSE; + +- if (!glnx_opendirat (AT_FDCWD, +- flatpak_file_get_path_cached (parent), +- TRUE, +- &parentfd, +- error)) +- return FALSE; +- +- /* The fds are closed by this call */ + if (!rewrite_export_dir (app, branch, arch, metadata, previous_ids, context, +- parentfd, name, source_path, ++ export_dfd, ".", "", + cancellable, error)) +- goto out; +- +- ret = TRUE; ++ return FALSE; + +-out: +- return ret; ++ return TRUE; + } + + +@@ -9127,7 +9107,6 @@ flatpak_dir_deploy (FlatpakDir *self, + g_autoptr(GFile) deploy_base = NULL; + glnx_autofd int deploy_base_dfd = -1; + g_autoptr(GFile) checkoutdir = NULL; +- g_autoptr(GFile) bindir = NULL; + g_autofree char *checkoutdirpath = NULL; + const char *checkoutdir_basename; + g_autoptr(GFile) real_checkoutdir = NULL; +@@ -9135,7 +9114,6 @@ flatpak_dir_deploy (FlatpakDir *self, + g_autoptr(GFile) deploy_data_file = NULL; + g_autoptr(GVariant) commit_data = NULL; + g_autoptr(GBytes) deploy_data = NULL; +- g_autoptr(GFile) export = NULL; + g_autoptr(GFile) extradir = NULL; + g_autoptr(GKeyFile) keyfile = NULL; + guint64 installed_size = 0; +@@ -9486,32 +9464,43 @@ flatpak_dir_deploy (FlatpakDir *self, + g_autofree char *escaped_branch = maybe_quote (ref_branch); + g_autofree char *escaped_arch = maybe_quote (ref_arch); + g_autofree char *bin_data = NULL; +- g_autoptr(GFile) wrapper = NULL; ++ glnx_autofd int export_dfd = -1; ++ glnx_autofd int bin_dfd = -1; + int r; + +- export = g_file_get_child (checkoutdir, "export"); +- bindir = g_file_get_child (export, "bin"); +- wrapper = g_file_get_child (bindir, ref_id); ++ export_dfd = glnx_chase_and_mkdirat (checkoutdir_dfd, "export", ++ GLNX_CHASE_RESOLVE_NO_SYMLINKS, ++ 0755, error); ++ if (export_dfd < 0) ++ return FALSE; + +- if (!flatpak_mkdir_p (bindir, cancellable, error)) ++ bin_dfd = glnx_chase_and_mkdirat (export_dfd, "bin", ++ GLNX_CHASE_RESOLVE_NO_SYMLINKS, ++ 0755, error); ++ if (bin_dfd < 0) + return FALSE; + + if (!flatpak_rewrite_export_dir (ref_id, ref_branch, ref_arch, +- keyfile, previous_ids, export, ++ keyfile, previous_ids, export_dfd, + cancellable, + error)) + return FALSE; ++ + if ((flatpak = g_getenv ("FLATPAK_BINARY")) == NULL) + flatpak = FLATPAK_BINDIR "/flatpak"; + + bin_data = g_strdup_printf ("#!/bin/sh\nexec %s run --branch=%s --arch=%s %s \"$@\"\n", + flatpak, escaped_branch, escaped_arch, escaped_app); +- if (!g_file_replace_contents (wrapper, bin_data, strlen (bin_data), NULL, FALSE, +- G_FILE_CREATE_REPLACE_DESTINATION, NULL, cancellable, error)) ++ ++ if (!glnx_file_replace_contents_at (bin_dfd, ref_id, ++ (const uint8_t *) bin_data, ++ strlen (bin_data), ++ GLNX_FILE_REPLACE_NODATASYNC, ++ cancellable, error)) + return FALSE; + + do +- r = fchmodat (AT_FDCWD, flatpak_file_get_path_cached (wrapper), 0755, 0); ++ r = fchmodat (bin_dfd, ref_id, 0755, 0); + while (G_UNLIKELY (r == -1 && errno == EINTR)); + if (r == -1) + return glnx_throw_errno_prefix (error, "fchmodat"); diff -Nru flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/dir-Use-fd-relative-operations-for-export-bin-removal-dur.patch flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/dir-Use-fd-relative-operations-for-export-bin-removal-dur.patch --- flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/dir-Use-fd-relative-operations-for-export-bin-removal-dur.patch 1970-01-01 00:00:00.000000000 +0000 +++ flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/dir-Use-fd-relative-operations-for-export-bin-removal-dur.patch 2026-09-28 13:13:01.000000000 +0000 @@ -0,0 +1,80 @@ +From: Sebastian Wick +Date: Tue, 11 Aug 2026 23:20:59 +0200 +Subject: dir: Use fd-relative operations for export/bin removal during deploy + +The export directory cleanup during deploy used flatpak_rm_rf which +wraps glnx_shutil_rm_rf_at(AT_FDCWD, path). The kernel resolves +intermediate symlinks in the path, so a malicious ostree commit with +"export" as a symlink causes flatpak_rm_rf(export/bin) to delete files +at the symlink target. On system installs (running as root), this is +arbitrary file deletion. + +This commit uses fd-based operations to prevent to prevent the symlink +attack. + +Resolves: CVE-2026-97023 +Resolves: https://github.com/flatpak/flatpak/security/advisories/GHSA-5p67-xh8x-rq54 +--- + common/flatpak-dir.c | 29 ++++++++++++++++++++++------- + 1 file changed, 22 insertions(+), 7 deletions(-) + +diff --git a/common/flatpak-dir.c b/common/flatpak-dir.c +index 1380a8a..60ea56f 100644 +--- a/common/flatpak-dir.c ++++ b/common/flatpak-dir.c +@@ -9413,12 +9413,23 @@ flatpak_dir_deploy (FlatpakDir *self, + return FALSE; + } + +- export = g_file_get_child (checkoutdir, "export"); +- + /* Never export any binaries bundled with the app */ +- bindir = g_file_get_child (export, "bin"); +- if (!flatpak_rm_rf (bindir, cancellable, error)) +- return FALSE; ++ { ++ g_autoptr(GError) local_error = NULL; ++ glnx_autofd int export_dfd = -1; ++ ++ export_dfd = flatpak_deploy_get_export_fd (checkoutdir_dfd, NULL, 0, &local_error); ++ if (export_dfd < 0 && ++ !g_error_matches (local_error, G_IO_ERROR, G_IO_ERROR_NOT_FOUND)) ++ { ++ g_propagate_error (error, g_steal_pointer (&local_error)); ++ return FALSE; ++ } ++ ++ if (export_dfd >= 0 && ++ !glnx_shutil_rm_rf_at (export_dfd, "bin", cancellable, error)) ++ return FALSE; ++ } + + if (flatpak_decomposed_is_runtime (ref)) + { +@@ -9464,20 +9475,24 @@ flatpak_dir_deploy (FlatpakDir *self, + } + + /* Runtime should never export anything */ +- if (!flatpak_rm_rf (export, cancellable, error)) ++ if (!glnx_shutil_rm_rf_at (checkoutdir_dfd, "export", cancellable, error)) + return FALSE; + } + else /* is app */ + { + g_autofree char *ref_arch = flatpak_decomposed_dup_arch (ref); + g_autofree char *ref_branch = flatpak_decomposed_dup_branch (ref); +- g_autoptr(GFile) wrapper = g_file_get_child (bindir, ref_id); + g_autofree char *escaped_app = maybe_quote (ref_id); + g_autofree char *escaped_branch = maybe_quote (ref_branch); + g_autofree char *escaped_arch = maybe_quote (ref_arch); + g_autofree char *bin_data = NULL; ++ g_autoptr(GFile) wrapper = NULL; + int r; + ++ export = g_file_get_child (checkoutdir, "export"); ++ bindir = g_file_get_child (export, "bin"); ++ wrapper = g_file_get_child (bindir, ref_id); ++ + if (!flatpak_mkdir_p (bindir, cancellable, error)) + return FALSE; + diff -Nru flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/dir-Use-fd-relative-operations-for-files-etc-during-runti.patch flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/dir-Use-fd-relative-operations-for-files-etc-during-runti.patch --- flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/dir-Use-fd-relative-operations-for-files-etc-during-runti.patch 1970-01-01 00:00:00.000000000 +0000 +++ flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/dir-Use-fd-relative-operations-for-files-etc-during-runti.patch 2026-09-28 13:13:01.000000000 +0000 @@ -0,0 +1,122 @@ +From: Sebastian Wick +Date: Tue, 11 Aug 2026 23:21:13 +0200 +Subject: dir: Use fd-relative operations for files/etc during runtime deploy +MIME-Version: 1.0 +Content-Type: text/plain; charset="utf-8" +Content-Transfer-Encoding: 8bit + +The runtime deploy path used GFile operations to manipulate files +inside files/etc (passwd, group, machine-id, resolv.conf). While +the "files" directory is validated with glnx_chaseat using +GLNX_CHASE_RESOLVE_NO_SYMLINKS, "etc" inside it is not checked. +A malicious runtime with files/etc as a symlink causes the GFile +operations (g_file_delete, g_file_replace_contents, +g_file_make_symbolic_link) to follow it and modify files at the +symlink target. On system installs (running as root), this modifies +arbitrary files — e.g. replacing /etc/resolv.conf. + +This commit uses fd-based operations to prevent to prevent the symlink +attack. + +Resolves: CVE-2026-97024 +Resolves: https://github.com/flatpak/flatpak/security/advisories/GHSA-8xgq-v545-vgvf +--- + common/flatpak-dir.c | 69 ++++++++++++++++++++++++++++++---------------------- + 1 file changed, 40 insertions(+), 29 deletions(-) + +diff --git a/common/flatpak-dir.c b/common/flatpak-dir.c +index 4b3595b..3d55f7a 100644 +--- a/common/flatpak-dir.c ++++ b/common/flatpak-dir.c +@@ -9110,7 +9110,6 @@ flatpak_dir_deploy (FlatpakDir *self, + g_autofree char *checkoutdirpath = NULL; + const char *checkoutdir_basename; + g_autoptr(GFile) real_checkoutdir = NULL; +- g_autoptr(GFile) files_etc = NULL; + g_autoptr(GFile) deploy_data_file = NULL; + g_autoptr(GVariant) commit_data = NULL; + g_autoptr(GBytes) deploy_data = NULL; +@@ -9413,43 +9412,55 @@ flatpak_dir_deploy (FlatpakDir *self, + { + /* Ensure that various files exist as regular files in /usr/etc, as we + want to bind-mount over them */ +- files_etc = g_file_resolve_relative_path (checkoutdir, "files/etc"); +- if (g_file_query_exists (files_etc, cancellable)) ++ g_autoptr(GError) local_error = NULL; ++ glnx_autofd int etc_dfd = -1; ++ ++ etc_dfd = flatpak_deploy_get_files_fd (checkoutdir_dfd, "etc", ++ GLNX_CHASE_MUST_BE_DIRECTORY, ++ &local_error); ++ if (etc_dfd < 0 && ++ !g_error_matches (local_error, G_IO_ERROR, G_IO_ERROR_NOT_FOUND)) + { +- static const char * const etcfiles[] = {"passwd", "group", "machine-id" }; +- g_autoptr(GFile) etc_resolve_conf = g_file_get_child (files_etc, "resolv.conf"); +- int i; +- for (i = 0; i < G_N_ELEMENTS (etcfiles); i++) ++ g_propagate_error (error, g_steal_pointer (&local_error)); ++ return FALSE; ++ } ++ g_clear_error (&local_error); ++ ++ if (etc_dfd >= 0) ++ { ++ static const char * const etcfiles[] = { ++ "passwd", "group", "machine-id", ++ }; ++ ++ for (size_t i = 0; i < G_N_ELEMENTS (etcfiles); i++) + { +- g_autoptr(GFile) etc_file = g_file_get_child (files_etc, etcfiles[i]); +- GFileType type; ++ struct stat stbuf; + +- type = g_file_query_file_type (etc_file, G_FILE_QUERY_INFO_NOFOLLOW_SYMLINKS, +- cancellable); +- if (type == G_FILE_TYPE_REGULAR) ++ if (!glnx_fstatat_allow_noent (etc_dfd, etcfiles[i], &stbuf, ++ AT_SYMLINK_NOFOLLOW, error)) ++ return FALSE; ++ if (errno == 0 && S_ISREG (stbuf.st_mode)) + continue; + +- if (type != G_FILE_TYPE_UNKNOWN) +- { +- /* Already exists, but not regular, probably symlink. Remove it */ +- if (!g_file_delete (etc_file, cancellable, error)) +- return FALSE; +- } +- +- if (!g_file_replace_contents (etc_file, "", 0, NULL, FALSE, +- G_FILE_CREATE_REPLACE_DESTINATION, +- NULL, cancellable, error)) ++ if (!glnx_file_replace_contents_at (etc_dfd, etcfiles[i], ++ (const guint8 *) "", 0, ++ GLNX_FILE_REPLACE_NODATASYNC, ++ cancellable, error)) + return FALSE; + } + +- if (g_file_query_exists (etc_resolve_conf, cancellable) && +- !g_file_delete (etc_resolve_conf, cancellable, error)) +- return FALSE; ++ if (!glnx_unlinkat (etc_dfd, "resolv.conf", 0, &local_error)) ++ { ++ if (!g_error_matches (local_error, G_IO_ERROR, G_IO_ERROR_NOT_FOUND)) ++ { ++ g_propagate_error (error, g_steal_pointer (&local_error)); ++ return FALSE; ++ } ++ g_clear_error (&local_error); ++ } + +- if (!g_file_make_symbolic_link (etc_resolve_conf, +- "/run/host/monitor/resolv.conf", +- cancellable, error)) +- return FALSE; ++ if (symlinkat ("/run/host/monitor/resolv.conf", etc_dfd, "resolv.conf") != 0) ++ return glnx_throw_errno_prefix (error, "symlinkat(files/etc/resolv.conf)"); + } + + /* Runtime should never export anything */ diff -Nru flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/dir-Use-fd-relative-operations-in-deploy_dir_is_locked.patch flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/dir-Use-fd-relative-operations-in-deploy_dir_is_locked.patch --- flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/dir-Use-fd-relative-operations-in-deploy_dir_is_locked.patch 1970-01-01 00:00:00.000000000 +0000 +++ flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/dir-Use-fd-relative-operations-in-deploy_dir_is_locked.patch 2026-09-28 13:13:01.000000000 +0000 @@ -0,0 +1,95 @@ +From: Sebastian Wick +Date: Tue, 11 Aug 2026 23:21:23 +0200 +Subject: dir: Use fd-relative operations in deploy_dir_is_locked + +dir_is_locked() used g_file_resolve_relative_path to construct the +path to files/.ref, then open() without O_NOFOLLOW. Since "files" is +validated as a non-symlink during deploy and ".ref" is atomically +created as a regular file, this is not exploitable through normal +install flow. However, the function should still use safe fd-relative +operations as defense-in-depth. + +Rename dir_is_locked to deploy_dir_is_locked to reflect that it +operates specifically on deploy directories, not arbitrary ones. + +Hardening related to CVE-2026-97023, CVE-2026-97024 + +Helps: https://github.com/flatpak/flatpak/security/advisories/GHSA-5p67-xh8x-rq54 +Helps: https://github.com/flatpak/flatpak/security/advisories/GHSA-8xgq-v545-vgvf +--- + common/flatpak-dir.c | 41 +++++++++++++++++++++++++---------------- + 1 file changed, 25 insertions(+), 16 deletions(-) + +diff --git a/common/flatpak-dir.c b/common/flatpak-dir.c +index 3d55f7a..3a04aed 100644 +--- a/common/flatpak-dir.c ++++ b/common/flatpak-dir.c +@@ -11606,27 +11606,36 @@ out: + } + + static gboolean +-dir_is_locked (GFile *dir) ++deploy_dir_is_locked (GFile *deploy_dir) + { ++ glnx_autofd int deploy_dfd = -1; ++ glnx_autofd int ref_path_fd = -1; + glnx_autofd int ref_fd = -1; + struct flock lock = {0}; +- g_autoptr(GFile) reffile = NULL; + +- reffile = g_file_resolve_relative_path (dir, "files/.ref"); ++ if (!glnx_opendirat (AT_FDCWD, flatpak_file_get_path_cached (deploy_dir), ++ FALSE, &deploy_dfd, NULL)) ++ return FALSE; + +- ref_fd = open (flatpak_file_get_path_cached (reffile), O_RDWR | O_CLOEXEC); +- if (ref_fd != -1) +- { +- lock.l_type = F_WRLCK; +- lock.l_whence = SEEK_SET; +- lock.l_start = 0; +- lock.l_len = 0; ++ ref_path_fd = flatpak_deploy_get_files_fd (deploy_dfd, ".ref", ++ GLNX_CHASE_MUST_BE_REGULAR, ++ NULL); ++ if (ref_path_fd < 0) ++ return FALSE; + +- if (fcntl (ref_fd, F_GETLK, &lock) == 0) +- return lock.l_type != F_UNLCK; +- } ++ ref_fd = glnx_fd_reopen (ref_path_fd, O_RDWR, NULL); ++ if (ref_fd < 0) ++ return FALSE; + +- return FALSE; ++ lock.l_type = F_WRLCK; ++ lock.l_whence = SEEK_SET; ++ lock.l_start = 0; ++ lock.l_len = 0; ++ ++ if (fcntl (ref_fd, F_GETLK, &lock) != 0) ++ return FALSE; ++ ++ return lock.l_type != F_UNLCK; + } + + gboolean +@@ -11754,7 +11763,7 @@ flatpak_dir_undeploy (FlatpakDir *self, + } + } + +- if (force_remove || !dir_is_locked (removed_subdir)) ++ if (force_remove || !deploy_dir_is_locked (removed_subdir)) + { + g_autoptr(GError) tmp_error = NULL; + +@@ -11951,7 +11960,7 @@ flatpak_dir_cleanup_removed (FlatpakDir *self, + g_autoptr(GFile) child = g_file_get_child (removed_dir, name); + + if (g_file_info_get_file_type (child_info) == G_FILE_TYPE_DIRECTORY && +- !dir_is_locked (child)) ++ !deploy_dir_is_locked (child)) + { + g_autoptr(GError) tmp_error = NULL; + if (!flatpak_rm_rf (child, cancellable, &tmp_error)) diff -Nru flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/run-Use-deploy-helper-to-open-runtime-files-directory.patch flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/run-Use-deploy-helper-to-open-runtime-files-directory.patch --- flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/run-Use-deploy-helper-to-open-runtime-files-directory.patch 1970-01-01 00:00:00.000000000 +0000 +++ flatpak-1.16.6/debian/patches/CVE-2026-97023-97024/run-Use-deploy-helper-to-open-runtime-files-directory.patch 2026-09-28 13:13:01.000000000 +0000 @@ -0,0 +1,60 @@ +From: Sebastian Wick +Date: Tue, 11 Aug 2026 23:21:31 +0200 +Subject: run: Use deploy helper to open runtime files directory + +The runtime files directory was opened with open() using O_PATH but +without symlink protection, unlike the app files path which used +O_NOFOLLOW. Since "files" is validated as a non-symlink during deploy, +this is not exploitable through normal install flow. However, the open +should still use safe fd-relative operations as defense-in-depth. + +Use flatpak_deploy_get_files_fd which validates the path with +glnx_chaseat(GLNX_CHASE_RESOLVE_NO_SYMLINKS), rejecting any symlink +at the directory boundary. + +Hardening related to CVE-2026-97023, CVE-2026-97024 + +Helps: https://github.com/flatpak/flatpak/security/advisories/GHSA-5p67-xh8x-rq54 +Helps: https://github.com/flatpak/flatpak/security/advisories/GHSA-8xgq-v545-vgvf +[smcv: Cherry-picked to 1.16.x, fixed merge conflict] +--- + common/flatpak-run.c | 11 ++++++++--- + 1 file changed, 8 insertions(+), 3 deletions(-) + +diff --git a/common/flatpak-run.c b/common/flatpak-run.c +index 2ba1099..396c49d 100644 +--- a/common/flatpak-run.c ++++ b/common/flatpak-run.c +@@ -3103,6 +3103,7 @@ flatpak_run_app (FlatpakDecomposed *app_ref, + gboolean sandboxed = (flags & FLATPAK_RUN_FLAG_SANDBOX) != 0; + gboolean parent_expose_pids = (flags & FLATPAK_RUN_FLAG_PARENT_EXPOSE_PIDS) != 0; + gboolean parent_share_pids = (flags & FLATPAK_RUN_FLAG_PARENT_SHARE_PIDS) != 0; ++ glnx_autofd int runtime_deploy_dfd = -1; + glnx_autofd int original_runtime_fd = -1; + g_autoptr(GFile) original_runtime_files = NULL; + g_autoptr(GFile) custom_runtime_files = NULL; +@@ -3228,6 +3229,11 @@ flatpak_run_app (FlatpakDecomposed *app_ref, + if (runtime_deploy == NULL) + return FALSE; + ++ if (!glnx_opendirat (AT_FDCWD, ++ flatpak_file_get_path_cached (flatpak_deploy_get_dir (runtime_deploy)), ++ FALSE, &runtime_deploy_dfd, error)) ++ return FALSE; ++ + runtime_deploy_data = flatpak_deploy_get_deploy_data (runtime_deploy, FLATPAK_DEPLOY_VERSION_ANY, cancellable, error); + if (runtime_deploy_data == NULL) + return FALSE; +@@ -3258,10 +3264,9 @@ flatpak_run_app (FlatpakDecomposed *app_ref, + + flatpak_context_dump (app_context, "Final context"); + original_runtime_files = flatpak_deploy_get_files (runtime_deploy); +- original_runtime_fd = open (flatpak_file_get_path_cached (original_runtime_files), +- O_PATH | O_CLOEXEC); ++ original_runtime_fd = flatpak_deploy_get_files_fd (runtime_deploy_dfd, NULL, 0, error); + if (original_runtime_fd < 0) +- return glnx_throw_errno_prefix (error, "Failed to open original runtime"); ++ return glnx_prefix_error (error, "Failed to open original runtime"); + + if (custom_runtime_fd >= 0) + { diff -Nru flatpak-1.16.6/debian/patches/CVE-2026-97025/oci-Stop-persisting-bearer-token-to-child-repo-on-disk.patch flatpak-1.16.6/debian/patches/CVE-2026-97025/oci-Stop-persisting-bearer-token-to-child-repo-on-disk.patch --- flatpak-1.16.6/debian/patches/CVE-2026-97025/oci-Stop-persisting-bearer-token-to-child-repo-on-disk.patch 1970-01-01 00:00:00.000000000 +0000 +++ flatpak-1.16.6/debian/patches/CVE-2026-97025/oci-Stop-persisting-bearer-token-to-child-repo-on-disk.patch 2026-09-28 13:13:01.000000000 +0000 @@ -0,0 +1,63 @@ +From: Sebastian Wick +Date: Wed, 23 Sep 2026 14:13:49 +0200 +Subject: oci: Stop persisting bearer token to child repo on disk + +The .token file was written into the child-oci directory so the +system helper could read it back for remote registry verification. +However, the system helper only ever opens the child-oci registry +as a local source (dfd != -1), and every code path that uses +self->token for HTTP requests is gated behind dfd == -1. The token +was never reachable since it was introduced in commit 5d8fd2d1b. + +Persisting credentials to a world-traversable directory in /var/tmp +is a security risk on multi-user systems. Remove the file write +from set_token and the file read from ensure_local. The token +remains available in memory for the client process that actually +needs it for remote access. + +Resolves: CVE-2026-97025 +Resolves: https://github.com/flatpak/flatpak/security/advisories/GHSA-7rvf-rqr3-43j4 +[smcv: Backport to 1.16.x] +--- + common/flatpak-oci-registry.c | 14 -------------- + 1 file changed, 14 deletions(-) + +diff --git a/common/flatpak-oci-registry.c b/common/flatpak-oci-registry.c +index 6021f03..2e6cf05 100644 +--- a/common/flatpak-oci-registry.c ++++ b/common/flatpak-oci-registry.c +@@ -247,12 +247,6 @@ flatpak_oci_registry_set_token (FlatpakOciRegistry *self, + { + g_free (self->token); + self->token = g_strdup (token); +- +- if (self->token) +- (void)glnx_file_replace_contents_at (self->dfd, ".token", +- (guchar *)self->token, +- strlen (self->token), +- 0, NULL, NULL); + } + + +@@ -469,7 +463,6 @@ flatpak_oci_registry_ensure_local (FlatpakOciRegistry *self, + int dfd; + g_autoptr(GError) local_error = NULL; + g_autoptr(GBytes) oci_layout_bytes = NULL; +- g_autoptr(GBytes) token_bytes = NULL; + gboolean not_json; + + if (self->dfd != -1) +@@ -531,13 +524,6 @@ flatpak_oci_registry_ensure_local (FlatpakOciRegistry *self, + else if (!verify_oci_version (oci_layout_bytes, ¬_json, cancellable, error)) + return FALSE; + +- if (self->dfd != -1) +- { +- token_bytes = local_load_file (self->dfd, ".token", cancellable, NULL); +- if (token_bytes != NULL) +- self->token = g_strndup (g_bytes_get_data (token_bytes, NULL), g_bytes_get_size (token_bytes)); +- } +- + if (self->dfd == -1 && local_dfd != -1) + self->dfd = g_steal_fd (&local_dfd); + diff -Nru flatpak-1.16.6/debian/patches/CVE-2026-97026/common-Restrict-tmpdir-permissions-from-0777-to-0755.patch flatpak-1.16.6/debian/patches/CVE-2026-97026/common-Restrict-tmpdir-permissions-from-0777-to-0755.patch --- flatpak-1.16.6/debian/patches/CVE-2026-97026/common-Restrict-tmpdir-permissions-from-0777-to-0755.patch 1970-01-01 00:00:00.000000000 +0000 +++ flatpak-1.16.6/debian/patches/CVE-2026-97026/common-Restrict-tmpdir-permissions-from-0777-to-0755.patch 2026-09-28 13:13:01.000000000 +0000 @@ -0,0 +1,34 @@ +From: Sebastian Wick +Date: Wed, 23 Sep 2026 14:14:13 +0200 +Subject: common: Restrict tmpdir permissions from 0777 to 0755 + +flatpak_allocate_tmpdir created child repo directories (repo- and +child-oci-) with mode 0777, allowing any local user to modify their +contents between the client pull and the system helper deploy. + +Use 0755 instead, which prevents other users from writing while +still allowing the revokefs-fuse frontend to read the backing store +directly. The frontend runs as the calling user while the writer +backend runs as the flatpak system user, so the frontend needs +read access to directories created by the backend. Mode 0700 would +break this. + +Resolves: CVE-2026-97026 +Resolves: https://github.com/flatpak/flatpak/security/advisories/GHSA-r9w3-qx54-qvc8 +--- + common/flatpak-utils.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/common/flatpak-utils.c b/common/flatpak-utils.c +index c549514..b4b8e55 100644 +--- a/common/flatpak-utils.c ++++ b/common/flatpak-utils.c +@@ -1786,7 +1786,7 @@ flatpak_allocate_tmpdir (int tmpdir_dfd, + g_auto(GLnxTmpDir) new_tmpdir = { 0, }; + /* No existing tmpdir found, create a new */ + +- if (!glnx_mkdtempat (dfd_iter.fd, tmpdir_name_template, 0777, ++ if (!glnx_mkdtempat (dfd_iter.fd, tmpdir_name_template, 0755, + &new_tmpdir, error)) + return FALSE; + diff -Nru flatpak-1.16.6/debian/patches/CVE-2026-97027/dir-Validate-Desktop-Entry-and-D-Bus-Service.patch flatpak-1.16.6/debian/patches/CVE-2026-97027/dir-Validate-Desktop-Entry-and-D-Bus-Service.patch --- flatpak-1.16.6/debian/patches/CVE-2026-97027/dir-Validate-Desktop-Entry-and-D-Bus-Service.patch 1970-01-01 00:00:00.000000000 +0000 +++ flatpak-1.16.6/debian/patches/CVE-2026-97027/dir-Validate-Desktop-Entry-and-D-Bus-Service.patch 2026-09-28 13:13:01.000000000 +0000 @@ -0,0 +1,399 @@ +From: =?utf-8?q?Markus_G=C3=B6llnitz?= +Date: Mon, 27 Jul 2026 23:08:39 +0200 +Subject: dir: Validate Desktop Entry and D-Bus Service +MIME-Version: 1.0 +Content-Type: text/plain; charset="utf-8" +Content-Transfer-Encoding: 8bit + +D-Bus Services and Desktop Entries could be extended +through custom keys. D-Bus daemons and desktop +environments augment Applications this way + +Besides validating Exec= and D-Bus Service Name=, these +could lead to denial of service, e.g. X-GNOME-AutoRestart +in Desktop Entries, or even code exection outside the +sandbox, e.g. SystemdService in D-Bus Services. + +The only reasonable way to ensure non of these make it +through, is exporting only know acceptable ones, instead +of hoping to aggregate every problematic one. + +See: https://specifications.freedesktop.org/desktop-entry/latest/index.html +See: https://dbus.freedesktop.org/doc/dbus-specification.html + +Resolves: CVE-2026-97027 +Resolves: https://github.com/flatpak/flatpak/security/advisories/GHSA-v64f-hrwr-j4vh +Signed-off-by: Markus Göllnitz +[smcv: Added CVE ID] +Signed-off-by: Simon McVittie +--- + common/flatpak-dir.c | 286 +++++++++++++++++++++++++++++++++++++++++++++++---- + tests/test-run.sh | 2 +- + 2 files changed, 265 insertions(+), 23 deletions(-) + +diff --git a/common/flatpak-dir.c b/common/flatpak-dir.c +index 5aa29ac..ad4def3 100644 +--- a/common/flatpak-dir.c ++++ b/common/flatpak-dir.c +@@ -291,6 +291,182 @@ enum { + #define OSTREE_GIO_FAST_QUERYINFO ("standard::name,standard::type,standard::size,standard::is-symlink,standard::symlink-target," \ + "unix::device,unix::inode,unix::mode,unix::uid,unix::gid,unix::rdev") + ++#define X_FLATPAK_KEY_ID "X-Flatpak" ++#define X_FLATPAK_KEY_RENAMED_FROM "X-Flatpak-RenamedFrom" ++#define X_FLATPAK_KEY_TAGS "X-Flatpak-Tags" ++ ++static const char * const allowed_desktop_entry_keys[] = { ++ /* OFFICIAL SPECIFICATION */ ++ /* Standardised fields that are safe for an app to specify: */ ++ "Actions", ++ "Categories", ++ "Comment", ++ "DBusActivatable", ++ "GenericName", ++ "Hidden", ++ "Icon", ++ "Implements", ++ "Keywords", ++ "MimeType", ++ "Name", ++ "NoDisplay", ++ "NotShowIn", ++ "OnlyShowIn", ++ "Path", ++ "PrefersNonDefaultGPU", ++ "SingleMainWindow", ++ "StartupNotify", ++ "StartupWMClass", ++ "Terminal", ++ "Type", ++ "Version", ++ ++ /* Unsafe to export without proper sanitisation or adjustments, but rewritten ++ * by Flatpak: */ ++ "Exec", ++ ++ /* Intentionally not exported, only useful for Type=Link and not ++ * Type=Application: ++ * ++ * "URL", ++ * ++ * Intentionally not exported, unsafe and unnecessary due sandbox being an ++ * app controlled environment: ++ * ++ * "TryExec", ++ */ ++ ++ /* CUSTOM EXTENSIONS */ ++ ++/* Keys controlled by Flatpak: */ ++ X_FLATPAK_KEY_ID, ++ X_FLATPAK_KEY_RENAMED_FROM, ++ X_FLATPAK_KEY_TAGS, ++ ++ /* Exported, because they are deemed harmless: */ ++ "X-AppInstall-Keywords", ++ "X-AppStream-Ignore", ++ "X-GNOME-FullName", ++ "X-GNOME-Gettext-Domain", ++ "X-GNOME-UsesNotifications", ++ "X-GNOME-SingleWindow", ++ "X-Meego-Priority", ++ "X-MultipleArgs", ++ "X-KDE-AliasFor", ++ "X-KDE-FormFactor", ++ "X-KDE-Keywords", ++ "X-KDE-PluginInfo-Author", ++ "X-KDE-PluginInfo-Email", ++ "X-KDE-PluginInfo-License", ++ "X-KDE-PluginInfo-Name", ++ "X-KDE-PluginInfo-Version", ++ "X-KDE-Priority", ++ "X-KDE-Submenu", ++ "X-KDE-Wayland-VirtualKeyboard", ++ "X-Plasma-API", ++ "X-Plasma-DBusRunner-Service", ++ "X-Plasma-DBusRunner-Path", ++ "X-Plasma-Request-Actions-Once", ++ "X-Plasma-Runner-Match-Regex", ++ "X-Plasma-Runner-Min-Letter-Count", ++ "X-Plasma-Runner-Syntax-Descriptions", ++ "X-Plasma-Runner-Syntaxes", ++ "X-Plasma-Runner-Unique-Results", ++ "X-Plasma-Runner-Weak-Results", ++ "X-Krita-Version", ++ "X-Phosh-Lockscreen-Actions", ++ "X-Phosh-UsesFeedback", ++ "X-Purism-FormFactor", ++ "X-SingleMainWindow", ++ "X-systemd-skip", ++ "X-Ubuntu-Gettext-Domain", ++ "X-Unity-IconBackgroundColor", ++ ++ /* Exported key, whose implications are only evaluated for ++ * $XDG_DATA_DIRS/krunner/dbusplugins, i.e. in the context of KRunner runners, ++ * but not in e.g. $XDG_DATA_DIRS/kio/servicemenus, because non of those other ++ * directories are exported: ++ */ ++ "X-KDE-ServiceTypes", ++ ++ /* Intentionally not exported, these are unnecessary or would not work with ++ * sandboxed Flatpak apps: ++ * ++ * "DocPath", ++ * "Encoding", ++ * "X-DocPath", ++ * "X-Geoclue-Reason", ++ * "X-GNOME-Bugzilla-Bugzilla", ++ * "X-GNOME-Bugzilla-Component", ++ * "X-GNOME-Bugzilla-Product", ++ * "X-GNOME-Bugzilla-Version", ++ * "X-GNOME-DocPath", ++ * "X-KDE-NativeMimeType", ++ */ ++ ++ /* Intentionally not exported, these show potential for sandbox or portal ++ * bypass, incl. inferring host file structure, denial of service, code ++ * execution on host: ++ * ++ * "AutostartCondition", ++ * "InitialPreference", ++ * "ServiceTypes", ++ * "X-DBUS-StartupType", ++ * "X-DBUS-ServiceName", ++ * "X-GIO-NoFuse", ++ * "X-GNOME-AutoRestart", ++ * "X-GNOME-Autostart-Delay", ++ * "X-GNOME-Autostart-enabled", ++ * "X-GNOME-Bugzilla-ExtraInfoScript", ++ * "X-GNOME-SearchProvider-Path", ++ * "X-GNOME-SearchProvider-Prefix", ++ * "X-KDE-autostart-after", ++ * "X-KDE-autostart-phase", ++ * "X-KDE-DBus-Restricted-Interfaces", ++ * "X-KDE-ExtraNativeMimeTypes", ++ * "X-KDE-PluginInfo-EnabledByDefault", ++ * "X-KDE-Protocols", ++ * "X-KDE-SubstituteUID", ++ * "X-KDE-Username", ++ */ ++ NULL ++}; ++ ++static const char * const allowed_desktop_entry_action_keys[] = { ++ "Exec", ++ "Icon", ++ "Name", ++ NULL ++}; ++ ++static const char * const allowed_dbus_service_keys[] = { ++ /* STANDARDISED FIELDS */ ++ "Exec", ++ "Name", ++ ++ /* CUSTOM EXTENSIONS */ ++ /* These fields were used by LocalSearch, but are no longer used and thus ++ * are not necessary to export: ++ * ++ * "Comment", ++ * "DisplayName", ++ * "NameSuffix", ++ * "Path", ++ */ ++ ++ /* Intentionally not exported, makes only sense when system-controlled: ++ * ++ * "AssumedAppArmorLabel", ++ */ ++ ++ /* Intentionally not exported, these show potential for sandbox bypass: ++ * ++ * "User", ++ * "SystemdService", ++ */ ++ NULL ++}; ++ + static const char * + get_config_dir_location (void) + { +@@ -7596,6 +7772,7 @@ export_desktop_file (const char *app, + gsize new_data_len; + g_autoptr(GKeyFile) keyfile = NULL; + g_auto(GStrv) groups = NULL; ++ g_auto(GStrv) intents = NULL; + g_autofree char *escaped_app = maybe_quote (app); + g_autofree char *escaped_branch = maybe_quote (branch); + g_autofree char *escaped_arch = maybe_quote (arch); +@@ -7629,30 +7806,41 @@ export_desktop_file (const char *app, + if (g_str_has_suffix (name, ".desktop")) + { + gsize length; +- g_auto(GStrv) tags = g_key_file_get_string_list (metadata, +- "Application", +- "tags", &length, +- NULL); ++ g_auto(GStrv) tags = NULL; ++ g_autofree gchar *type = NULL; ++ ++ tags = g_key_file_get_string_list (metadata, ++ "Application", ++ "tags", &length, ++ NULL); ++ ++ intents = g_key_file_get_string_list (keyfile, G_KEY_FILE_DESKTOP_GROUP, ++ "Implements", NULL, NULL); ++ ++ type = g_key_file_get_string (keyfile, G_KEY_FILE_DESKTOP_GROUP, ++ G_KEY_FILE_DESKTOP_KEY_TYPE, error); ++ ++ if (type == NULL) ++ return FALSE; ++ ++ if (g_strcmp0 (type, G_KEY_FILE_DESKTOP_TYPE_APPLICATION) != 0 && ++ g_strcmp0 (type, "Service") != 0) ++ { ++ return flatpak_fail_error (error, FLATPAK_ERROR_EXPORT_FAILED, ++ _("Desktop Entry '%s' neither has Type=Application nor Type=Service"), ++ name); ++ } + + if (tags != NULL) + { + g_key_file_set_string_list (keyfile, + G_KEY_FILE_DESKTOP_GROUP, +- "X-Flatpak-Tags", ++ X_FLATPAK_KEY_TAGS, + (const char * const *) tags, length); + } + + /* Add a marker so consumers can easily find out that this launches a sandbox */ +- g_key_file_set_string (keyfile, G_KEY_FILE_DESKTOP_GROUP, "X-Flatpak", app); +- +- /* Disable krunner dbusplugins by default, so that flatpak applications cannot +- * unintentionally grab sensitive search data. +- */ +- if (g_key_file_get_boolean (keyfile, G_KEY_FILE_DESKTOP_GROUP, +- "X-KDE-PluginInfo-EnabledByDefault", NULL)) +- { +- g_key_file_set_boolean (keyfile, G_KEY_FILE_DESKTOP_GROUP, "X-KDE-PluginInfo-EnabledByDefault", FALSE); +- } ++ g_key_file_set_string (keyfile, G_KEY_FILE_DESKTOP_GROUP, X_FLATPAK_KEY_ID, app); + + /* If the app has been renamed, add its old .desktop filename to + * X-Flatpak-RenamedFrom in the new .desktop file, taking care not to +@@ -7660,10 +7848,9 @@ export_desktop_file (const char *app, + */ + if (previous_ids != NULL) + { +- const char *X_FLATPAK_RENAMED_FROM = "X-Flatpak-RenamedFrom"; + g_auto(GStrv) renamed_from = g_key_file_get_string_list (keyfile, + G_KEY_FILE_DESKTOP_GROUP, +- X_FLATPAK_RENAMED_FROM, ++ X_FLATPAK_KEY_RENAMED_FROM, + NULL, NULL); + g_autoptr(GPtrArray) merged = g_ptr_array_new_with_free_func (g_free); + g_autoptr(GHashTable) seen = g_hash_table_new (g_str_hash, g_str_equal); +@@ -7708,7 +7895,7 @@ export_desktop_file (const char *app, + g_ptr_array_add (merged, NULL); + g_key_file_set_string_list (keyfile, + G_KEY_FILE_DESKTOP_GROUP, +- X_FLATPAK_RENAMED_FROM, ++ X_FLATPAK_KEY_RENAMED_FROM, + (const char * const *) merged->pdata, + merged->len - 1); + } +@@ -7725,12 +7912,67 @@ export_desktop_file (const char *app, + g_autoptr(GString) new_exec = NULL; + g_auto(GStrv) flatpak_run_opts = g_key_file_get_string_list (keyfile, groups[i], "X-Flatpak-RunOptions", NULL, NULL); + g_autofree char *flatpak_run_args = format_flatpak_run_args_from_run_opts (flatpak_run_opts); ++ g_auto(GStrv) keys_for_group = NULL; ++ const char * const *allowed_keys; + + g_key_file_remove_key (keyfile, groups[i], "X-Flatpak-RunOptions", NULL); +- g_key_file_remove_key (keyfile, groups[i], "TryExec", NULL); + +- /* Remove this to make sure nothing tries to execute it outside the sandbox*/ +- g_key_file_remove_key (keyfile, groups[i], "X-GNOME-Bugzilla-ExtraInfoScript", NULL); ++ keys_for_group = g_key_file_get_keys (keyfile, groups[i], NULL, error); ++ ++ if (keys_for_group == NULL) ++ return FALSE; ++ ++ if (g_str_has_suffix (name, ".desktop") && ++ g_strcmp0 (groups[i], G_KEY_FILE_DESKTOP_GROUP) == 0) ++ { ++ allowed_keys = allowed_desktop_entry_keys; ++ } ++ else if (g_str_has_suffix (name, ".desktop") && ++ g_str_has_prefix (groups[i], "Desktop Action ")) ++ { ++ allowed_keys = allowed_desktop_entry_action_keys; ++ } ++ else if (g_str_has_suffix (name, ".desktop") && ++ intents != NULL && ++ g_strv_contains ((const char * const *) intents, groups[i])) ++ { ++ continue; ++ } ++ else if (g_str_has_suffix (name, ".service") && ++ g_strcmp0 (groups[i], "D-BUS Service") == 0) ++ { ++ allowed_keys = allowed_dbus_service_keys; ++ } ++ else ++ { ++ if (!g_key_file_remove_group (keyfile, groups[i], error)) ++ return FALSE; ++ continue; ++ } ++ ++ for (size_t k = 0; keys_for_group[k] != NULL; k++) ++ { ++ char *locale_suffix; ++ g_autofree char *base_key = NULL; ++ ++ locale_suffix = g_strrstr (keys_for_group[k], "["); ++ ++ if (locale_suffix != NULL && g_str_has_suffix (locale_suffix, "]")) ++ { ++ base_key = g_strndup (keys_for_group[k], ++ strlen (keys_for_group[k]) - strlen (locale_suffix)); ++ } ++ else ++ { ++ base_key = g_strdup (keys_for_group[k]); ++ } ++ ++ if (!g_strv_contains (allowed_keys, base_key)) ++ { ++ if (!g_key_file_remove_key (keyfile, groups[i], keys_for_group[k], error)) ++ return FALSE; ++ } ++ } + + new_exec = g_string_new (""); + if ((flatpak = g_getenv ("FLATPAK_BINARY")) == NULL) +@@ -9487,7 +9729,7 @@ rewrite_one_dynamic_launcher (const char *portal_desktop_dir, + g_warning ("Error encountered loading key file %s: %s", desktop_path, local_error->message); + return; + } +- if (!g_key_file_has_key (old_key_file, G_KEY_FILE_DESKTOP_GROUP, "X-Flatpak", NULL)) ++ if (!g_key_file_has_key (old_key_file, G_KEY_FILE_DESKTOP_GROUP, X_FLATPAK_KEY_ID, NULL)) + { + g_info ("Ignoring non-Flatpak dynamic launcher: %s", desktop_path); + return; +diff --git a/tests/test-run.sh b/tests/test-run.sh +index 2e5cc5c..815d920 100644 +--- a/tests/test-run.sh ++++ b/tests/test-run.sh +@@ -51,7 +51,7 @@ assert_file_has_content $FL_DIR/exports/share/applications/org.test.Hello.deskto + assert_has_file $FL_DIR/exports/share/gnome-shell/search-providers/org.test.Hello.search-provider.ini + assert_file_has_content $FL_DIR/exports/share/gnome-shell/search-providers/org.test.Hello.search-provider.ini "^DefaultDisabled=true$" + assert_has_file $FL_DIR/exports/share/krunner/dbusplugins/org.test.Hello.desktop +-assert_file_has_content $FL_DIR/exports/share/krunner/dbusplugins/org.test.Hello.desktop "^X-KDE-PluginInfo-EnabledByDefault=false$" ++assert_not_file_has_content $FL_DIR/exports/share/krunner/dbusplugins/org.test.Hello.desktop "^X-KDE-PluginInfo-EnabledByDefault=.*$" + assert_has_file $FL_DIR/exports/share/icons/hicolor/64x64/apps/org.test.Hello.png + assert_not_has_file $FL_DIR/exports/share/icons/hicolor/64x64/apps/dont-export.png + assert_has_file $FL_DIR/exports/share/icons/HighContrast/64x64/apps/org.test.Hello.png diff -Nru flatpak-1.16.6/debian/patches/CVE-2026-97029/common-Put-each-bubblewrap-child-process-in-its-own-proce.patch flatpak-1.16.6/debian/patches/CVE-2026-97029/common-Put-each-bubblewrap-child-process-in-its-own-proce.patch --- flatpak-1.16.6/debian/patches/CVE-2026-97029/common-Put-each-bubblewrap-child-process-in-its-own-proce.patch 1970-01-01 00:00:00.000000000 +0000 +++ flatpak-1.16.6/debian/patches/CVE-2026-97029/common-Put-each-bubblewrap-child-process-in-its-own-proce.patch 2026-09-28 13:13:01.000000000 +0000 @@ -0,0 +1,34 @@ +From: Simon McVittie +Date: Fri, 11 Sep 2026 18:28:10 +0100 +Subject: common: Put each bubblewrap child process in its own process group + +This prevents sandboxed processes from being able to kill processes +outside the sandbox with `kill (0, SIGNAL)`. The only process they can +kill like this will be the `bwrap` supervisor, which just terminates +the sandbox when killed. + +Resolves: CVE-2026-97029 +Resolves: https://github.com/flatpak/flatpak/security/advisories/GHSA-f3p8-vr7v-gxf2 +Signed-off-by: Simon McVittie +--- + common/flatpak-bwrap.c | 7 +++++++ + 1 file changed, 7 insertions(+) + +diff --git a/common/flatpak-bwrap.c b/common/flatpak-bwrap.c +index acec2ab..10b36e5 100644 +--- a/common/flatpak-bwrap.c ++++ b/common/flatpak-bwrap.c +@@ -511,6 +511,13 @@ flatpak_bwrap_child_setup (GArray *fd_array, + { + int i; + ++ /* If possible, start a new process group for the child. ++ * This avoids a sandboxed process being able to call kill (0, SIGNAL) ++ * and have it affect processes outside the sandbox. ++ * If this fails because we are already a process group leader, ignore: ++ * presumably in that case there is nothing else in our process group. */ ++ setpgid (0, 0); ++ + /* There is a dead-lock in glib versions before 2.60 when it closes + * the fds. See: https://gitlab.gnome.org/GNOME/glib/merge_requests/490 + * This was hitting the test-suite a lot, so we work around it by using diff -Nru flatpak-1.16.6/debian/patches/series flatpak-1.16.6/debian/patches/series --- flatpak-1.16.6/debian/patches/series 2026-08-11 13:03:38.000000000 +0000 +++ flatpak-1.16.6/debian/patches/series 2026-09-28 13:13:01.000000000 +0000 @@ -37,3 +37,15 @@ GHSA-fqx6-vh4p-42cg-GHSA-8qxj-x646-phcm/dir-Use-chaseat-in-extract_extra_data-to-prevent-path-tra.patch GHSA-fqx6-vh4p-42cg-GHSA-8qxj-x646-phcm/dir-Use-chaseat-in-apply_extra_data-to-prevent-path-trave.patch GHSA-fqx6-vh4p-42cg-GHSA-8qxj-x646-phcm/utils-Remove-unused-GFile-based-flatpak_cp_a.patch +CVE-2026-97029/common-Put-each-bubblewrap-child-process-in-its-own-proce.patch +CVE-2026-97027/dir-Validate-Desktop-Entry-and-D-Bus-Service.patch +CVE-2026-97023-97024/dir-Add-fd-relative-helpers-for-accessing-deploy-director.patch +CVE-2026-97023-97024/dir-Use-fd-relative-operations-for-export-bin-removal-dur.patch +CVE-2026-97023-97024/dir-Use-fd-relative-operations-for-app-export-during-depl.patch +CVE-2026-97023-97024/dir-Use-fd-relative-operations-for-files-etc-during-runti.patch +CVE-2026-97023-97024/dir-Use-fd-relative-operations-in-deploy_dir_is_locked.patch +CVE-2026-97023-97024/run-Use-deploy-helper-to-open-runtime-files-directory.patch +CVE-2026-97023-97024/dir-Reuse-app_files_dfd-for-.ref-write-during-deploy.patch +CVE-2026-97023-97024/dir-Use-deploy-helpers-in-apply_extra_data-and-flatpak_di.patch +CVE-2026-97025/oci-Stop-persisting-bearer-token-to-child-repo-on-disk.patch +CVE-2026-97026/common-Restrict-tmpdir-permissions-from-0777-to-0755.patch