Flatpak 1.18.4 Releases With Six Security Fixes, Including Two Root File-Destruction Bugs
Flatpak 1.18.4 has been released today, closing six vulnerabilities, two of which let a malicious app empty or delete host files like /etc/passwd as root during an upgrade. The two headline bugs are a resolv.conf symlink overwrite (CVE-2026-97024) and a path-traversal deletion (CVE-2026-97023), which are both rated CVSS 7.1 High and require the root system-helper context. This continues a security-heavy stretch for the project, following 1.18.1's nine-vulnerability drop and a series of stability patches through September. Flatpak recommends updating to 1.18.4 or later, and keeping bundled bubblewrap and xdg-dbus-proxy current.
Flatpak 1.18.4 Releases With Six Security Fixes, Including Two Root File-Destruction Bugs
Flatpak 1.18.4 has been released, addressing six security vulnerabilities, including two critical bugs that could allow malicious apps to delete or empty host files as root during upgrades. The two main vulnerabilities involve a resolv.conf symlink overwrite and a path-traversal deletion, both rated CVSS 7.1 High, which could lead to significant data loss. This release continues a trend of security-focused updates for Flatpak, following a previous release that fixed nine vulnerabilities and reflects ongoing efforts to enhance system security amid rising privilege escalation issues. Users are urged to update to version 1.18.4 or later and to ensure that bundled components like bubblewrap and xdg-dbus-proxy are also up-to-date to maintain a secure environment
