Fixes for CVE-2026-34078, CVE-2026-34079, GHSA-2fxp-43j9-pwvc and GHSA-89xm-3m96-w3jg
Logout Required
After installing this update it is required that you logout of
your current user session and log back in to ensure the changes
supplied by this update are applied properly.
This update has been submitted for testing by amigadave.
This update has been submitted for testing by amigadave.
This update's test gating status has been changed to 'waiting'.
This update's test gating status has been changed to 'waiting'.
This update's test gating status has been changed to 'passed'.
This update has been pushed to testing.
seems the .4 version has a regression that breaks atleast some chromium based browser flatpaks
fix is in .5 https://github.com/flatpak/flatpak/releases
Bodhi is disabling automatic push to stable due to negative karma. The maintainer may push manually if they determine that the issue is not severe.
Should hold for 1.17.5 https://github.com/flatpak/flatpak/releases/tag/1.17.5
Yup, this "security fix" breaks applications, including Steam: https://github.com/flatpak/flatpak/issues/6568
I also hit the Steam issue. It's a nasty one because it looks like Steam's at fault. +1 for 1.17.5 ASAP
This update has been obsoleted.
The regressions have been fixed in the subsequent 1.17.5 and 1.17.6 releases.