PT-2021-1501 · Flatpak+9 · Flatpak+9

Published

2020-09-24

·

Updated

2024-10-03

·

CVE-2021-41133

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Flatpak versions prior to 1.10.4 and 1.12.0
Description: The issue is related to the lack of blocking in the seccomp filter for mount-related system calls, which can be exploited to gain access to confidential data, disrupt its integrity, and cause a denial of service. Flatpak apps with direct access to AF UNIX sockets, such as those used by Wayland, Pipewire, or pipewire-pulse, can trick portals and other host-OS services into treating the Flatpak app as a non-sandboxed host-OS process. This can be achieved by manipulating the VFS using recent mount-related syscalls to substitute a crafted /.flatpak-info or make that file disappear entirely. Protocols operating entirely over the D-Bus session bus, system bus, or accessibility bus are not affected due to the use of a proxy process xdg-dbus-proxy.
Recommendations: For versions prior to 1.10.4 and 1.12.0, upgrade to a patched version, as patches exist for versions 1.10.4 and 1.12.0, and a patch for version 1.8.2 is being planned. There are no workarounds aside from upgrading to a patched version. As a temporary workaround, consider restricting the use of AF UNIX sockets, such as those used by Wayland, Pipewire, or pipewire-pulse, to minimize the risk of exploitation.

Fix

RCE

Weakness Enumeration

Related Identifiers

ALEA-2021:4539
ALSA-2021:4042
ALT-PU-2020-2869
ALT-PU-2021-3016
ALT-PU-2021-3551
BDU:2022-00259
CESA-2021_4042
CESA-2021_4044
CVE-2021-41133
DSA-4984-1
GHSA-67H7-W3JQ-VH4Q
MGASA-2021-0486
OESA-2021-1404
OPENSUSE-SU-2021:1400-1
OPENSUSE-SU-2021:3472-1
OPENSUSE-SU-2021_1400-1
OPENSUSE-SU-2021_3472-1
OPENSUSE-SU-2024:11574-1
RHSA-2021:4042
RHSA-2021:4044
RHSA-2021:4106
RHSA-2021:4107
RHSA-2021_4042
RHSA-2021_4044
RLSA-2021:4042
ROSA-SA-2024-2487
SUSE-SU-2021:3472-1
SUSE-SU-2021_3472-1
SUSE-SU-2022:3284-1
SUSE-SU-2022:3439-1
SUSE-SU-2022_3439-1
USN-5191-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Flatpak
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu