INFSA-2024:3961: Flatpak security update
Information about definition
Identificator: INFSA-2024:3961
Type: security
Release date: 2024-08-23 19:30:10 UTC
Information about package
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux.
Vulnerabilities description
- CVE-2024-32462
A flaw was found in Flatpak, a system for building, distributing, and running sandboxed desktop applications on Linux. Normally, the "--command" argument of "flatpak run" expects being given a command to run in the specified Flatpak app, along with optional arguments. However, it is possible to pass bwrap arguments to "--command=" instead, such as "--bind". It is possible to pass an arbitrary "commandline" to the portal interface "org.freedesktop.portal.Background.RequestBackground" within the Flatpak app. This is normally safe because it can only specify a command that exists inside the sandbox. When a crafted "commandline" is converted into a "--command" and arguments, the app could achieve the same effect of passing arguments directly to bwrap to achieve sandbox escape.
Severity level
CVE | Score CVSS 2.0 | Score CVSS 3.x | Score CVSS 4.0 |
---|---|---|---|
NIST — CVE-2024-32462
|
no information | 8.4 | no information |
Updated packages