PT-2023-9222 · Flatpak+7 · Flatpak+7

Jakub Wilk

·

Published

2023-03-16

·

Updated

2024-06-27

·

CVE-2023-28100

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Flatpak versions prior to 1.10.8 Flatpak versions prior to 1.12.8 Flatpak versions prior to 1.14.4 Flatpak versions prior to 1.15.4
Description The issue is related to the ioctl component of the Flatpak tool for managing applications and environments. It involves copying text from a virtual console and pasting it into the command buffer, from which the command might be run after the Flatpak app has exited. This can lead to a denial of service. The vulnerability is specific to Linux virtual consoles such as /dev/tty1, /dev/tty2, and so on. Graphical terminal emulators like xterm, gnome-terminal, and Konsole are unaffected.
Recommendations For versions prior to 1.10.8, update to version 1.10.8 or later. For versions prior to 1.12.8, update to version 1.12.8 or later. For versions prior to 1.14.4, update to version 1.14.4 or later. For versions prior to 1.15.4, update to version 1.15.4 or later. As a temporary workaround, do not run Flatpak on a Linux virtual console. Instead, use it in a Wayland or X11 graphical environment.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:6518
ALSA-2023:7038
ALT-PU-2023-1477
ALT-PU-2023-1512
BDU:2024-04881
CESA-2023_7038
CVE-2023-28100
GHSA-7QPW-3VJV-XRQP
MGASA-2023-0115
OESA-2024-1423
OESA-2024-1424
OESA-2024-1425
OESA-2024-1426
OPENSUSE-SU-2024:12800-1
RHSA-2023:6518
RHSA-2023:7038
RHSA-2023_6518
RHSA-2023_7038
RLSA-2023:6518
SUSE-SU-2023:1712-1
SUSE-SU-2023:1713-1
SUSE-SU-2023:1714-1
SUSE-SU-2023:1715-1
SUSE-SU-2023_1712-1
SUSE-SU-2023_1713-1
SUSE-SU-2023_1714-1
SUSE-SU-2023_1715-1

Affected Products

Alt Linux
Almalinux
Centos
Flatpak
Red Hat
Red Os
Rocky Linux
Suse