- Issued:
- 2023-05-09
- Updated:
- 2023-05-09
RHBA-2023:2664 - Bug Fix Advisory
Synopsis
Flatpak Container Images
Type/Severity
Bug Fix Advisory
Topic
Updated flatpak-runtime and flatpak-sdk container images are now available in the Red Hat Container Registry.
Description
Flatpak is a system for running graphical applications as containers. A Flatpak application has access to content from two container images - the application itself, and the runtime image. To build against a particular runtime image, a corresponding SDK image is used.
flatpak-runtime provides the runtime image and flatpak-sdk provides the SDK image.
This updates the flatpak-runtime and the flatpak-sdk container images in the Red Hat Container Registry.
Solution
To install and use the Flatpak SDK and runtime, you need Flatpak-1.6 or
newer installed. This gives the support for distributing Flatpaks using a
container registry. The necessary update to Flatpak-1.6 is part of Red Hat
Enterprise Linux 8.2.
After updating the Flatpak packages, add the Flatpak remote to your system.
This enables the Flatpak client and gnome-software to find RHEL Flatpak
content available on the Red Hat Container Catalog:
flatpak remote-add rhel https://flatpaks.redhat.io/rhel.flatpakrepo
Provide the credentials for your Red Hat Enterprise Linux account:
podman login registry.redhat.io
Podman only saves credentials until the user logs out. To save your
credentials permanently, run:
cp $XDG_RUNTIME_DIR/containers/auth.json
$HOME/.config/flatpak/oci-auth.json
To enable the RHEL Flatpak remote for a set of workstations within an
organization, you should use a Registry Service Account. Credentials can be
installed system-wide at /etc/flatpak/oci-auth.json.
Then, you can install the runtime and the SDK:
flatpak install rhel com.redhat.Platform//el8
flatpak install rhel com.redhat.Sdk//el8
Generally, you do not need to install the runtime explicitly. It is
installed along with an application that uses it.
If you have previously installed the runtime or SDK, you can update to the latest version by running:
flatpak update
The SDK is used by using flatpak-builder with a manifest that includes:
{
[...]
"runtime": "com.redhat.Platform",
"runtime-version": "el8",
"sdk": "com.redhat.Sdk",
}
Affected Products
- Red Hat Enterprise Linux for x86_64 9 x86_64
- Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64
- Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4 x86_64
- Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.2 x86_64
- Red Hat Enterprise Linux Server - AUS 9.6 x86_64
- Red Hat Enterprise Linux Server - AUS 9.4 x86_64
- Red Hat Enterprise Linux Server - AUS 9.2 x86_64
- Red Hat Enterprise Linux for IBM z Systems 9 s390x
- Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x
- Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.4 s390x
- Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.2 s390x
- Red Hat Enterprise Linux for Power, little endian 9 ppc64le
- Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le
- Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.4 ppc64le
- Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.2 ppc64le
- Red Hat Enterprise Linux for ARM 64 9 aarch64
- Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64
- Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4 aarch64
- Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.2 aarch64
- Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le
- Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le
- Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le
- Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64
- Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64
- Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64
- Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64
- Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64
- Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64
- Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x
- Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x
- Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x
Fixes
- BZ - 2006186 - Work around Flatpak issues with %{_userunitdir} (needed for 9.0.0-beta LibreOffice flatpak)
- BZ - 2150816 - Update flatpak-runtime and flatpak-sdk to incorporate fontconfig changes
- BZ - 2164186 - rebuild of flatpak-runtime-container 9.2
- BZ - 2164187 - rebuild of flatpak-sdk-container 9.2
- BZ - 2164441 - Update flatpak-build-base, flatpak-runtime and flatpak-sdk for 9.2
CVEs
- CVE-2020-17049
- CVE-2021-26341
- CVE-2021-33655
- CVE-2021-44648
- CVE-2021-46829
- CVE-2022-1462
- CVE-2022-1789
- CVE-2022-1882
- CVE-2022-1920
- CVE-2022-1921
- CVE-2022-1922
- CVE-2022-1923
- CVE-2022-1924
- CVE-2022-1925
- CVE-2022-2122
- CVE-2022-2196
- CVE-2022-2663
- CVE-2022-3028
- CVE-2022-3204
- CVE-2022-3358
- CVE-2022-3435
- CVE-2022-3522
- CVE-2022-3524
- CVE-2022-3566
- CVE-2022-3567
- CVE-2022-3570
- CVE-2022-3597
- CVE-2022-3598
- CVE-2022-3599
- CVE-2022-3619
- CVE-2022-3623
- CVE-2022-3625
- CVE-2022-3626
- CVE-2022-3627
- CVE-2022-3628
- CVE-2022-3640
- CVE-2022-3707
- CVE-2022-3970
- CVE-2022-4128
- CVE-2022-4129
- CVE-2022-4645
- CVE-2022-20141
- CVE-2022-21505
- CVE-2022-24765
- CVE-2022-28388
- CVE-2022-28805
- CVE-2022-29187
- CVE-2022-33743
- CVE-2022-36227
- CVE-2022-39188
- CVE-2022-39189
- CVE-2022-39253
- CVE-2022-39260
- CVE-2022-40023
- CVE-2022-41674
- CVE-2022-42703
- CVE-2022-42720
- CVE-2022-42721
- CVE-2022-42722
- CVE-2022-42896
- CVE-2022-43750
- CVE-2022-47929
- CVE-2022-48337
- CVE-2022-48338
- CVE-2022-48339
- CVE-2023-0394
- CVE-2023-0461
- CVE-2023-0590
- CVE-2023-1195
- CVE-2023-1382
- CVE-2023-1999
- CVE-2023-2491
- CVE-2023-25136
- CVE-2023-27535
- CVE-2023-30774
- CVE-2023-30775
References
(none)
x86_64
| rhel9/flatpak-runtime@sha256:0693458eed2c8253d60af9ec23dbb418aff224cd6822e0d9c6e231dffd995f5c |
| rhel9/flatpak-sdk@sha256:c13a157d1e2cf397346cb303391225891524b1433828c39d4257273822664104 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.