INFSA-2024:3961: Flatpak security update

Information about definition

Identificator: INFSA-2024:3961

Type: security

Release date: 2024-08-23 19:30:10 UTC

Information about package

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux.

Vulnerabilities description

  • CVE-2024-32462

    A flaw was found in Flatpak, a system for building, distributing, and running sandboxed desktop applications on Linux. Normally, the "--command" argument of "flatpak run" expects being given a command to run in the specified Flatpak app, along with optional arguments. However, it is possible to pass bwrap arguments to "--command=" instead, such as "--bind". It is possible to pass an arbitrary "commandline" to the portal interface "org.freedesktop.portal.Background.RequestBackground" within the Flatpak app. This is normally safe because it can only specify a command that exists inside the sandbox. When a crafted "commandline" is converted into a "--command" and arguments, the app could achieve the same effect of passing arguments directly to bwrap to achieve sandbox escape.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
no information 8.4 no information
Critical, important, moderate, low

Updated packages