PT-2024-2946 · Flatpak+10 · Flatpak+10

Gergo Koteles

·

Published

2024-04-18

·

Updated

2025-10-02

·

CVE-2024-32462

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Flatpak versions prior to 1.10.9 Flatpak versions prior to 1.12.9 Flatpak versions prior to 1.14.6 Flatpak versions prior to 1.15.8
Description The issue is related to a sandbox escape vulnerability in Flatpak, which is a system for building, distributing, and running sandboxed desktop applications on Linux. A malicious or compromised Flatpak app could execute arbitrary code outside its sandbox by passing bwrap arguments to the --command option, such as --bind. This can be achieved by passing an arbitrary commandline to the portal interface org.freedesktop.portal.Background.RequestBackground from within a Flatpak app. The vulnerability can be used to escape the sandbox and access files in the underlying system.
Recommendations For versions prior to 1.10.9, update to version 1.10.9 or later. For versions prior to 1.12.9, update to version 1.12.9 or later. For versions prior to 1.14.6, update to version 1.14.6 or later. For versions prior to 1.15.8, update to version 1.15.8 or later. As a temporary workaround, consider passing the -- argument to bwrap, which makes it stop processing options. Additionally, xdg-desktop-portal version 1.18.4 will mitigate this vulnerability by only allowing Flatpak apps to create .desktop files for commands that do not start with --.

Exploit

Fix

Argument Injection

Weakness Enumeration

Related Identifiers

ALSA-2024:3959
ALSA-2024:3961
ALSA-2024_3959
ALSA-2024_3961
ALT-PU-2024-6822
ALT-PU-2024-6954
ALT-PU-2024-6956
BDU:2024-03113
CESA-2024_3961
CVE-2024-32462
DSA-5666-1
GHSA-PHV6-CPC2-2FGJ
INFSA-2024_3959
INFSA-2024_3961
MGASA-2024-0229
OESA-2024-1490
OPENSUSE-SU-2024:13899-1
OPENSUSE-SU-2024:13985-1
OPENSUSE-SU-2024_1535-1
OPENSUSE-SU-2024_1536-1
OPENSUSE-SU-2024_1803-1
OPENSUSE-SU-2024_1806-1
OPENSUSE-SU-2024_2067-1
RHSA-2024:3959
RHSA-2024:3960
RHSA-2024:3961
RHSA-2024:3962
RHSA-2024:3963
RHSA-2024:3969
RHSA-2024:3970
RHSA-2024:3979
RHSA-2024:3980
RHSA-2024_3959
RHSA-2024_3961
RHSA-2024_3980
RLSA-2024:3959
RLSA-2024:3961
ROSA-SA-2024-2487
SUSE-RU-2025:0145-1
SUSE-SU-2024:1535-1
SUSE-SU-2024:1536-1
SUSE-SU-2024:1547-1
SUSE-SU-2024:1548-1
SUSE-SU-2024:1803-1
SUSE-SU-2024:1806-1
SUSE-SU-2024:1831-1
SUSE-SU-2024:1832-1
SUSE-SU-2024:2067-1
SUSE-SU-2024_1535-1
SUSE-SU-2024_1536-1
SUSE-SU-2024_1547-1
SUSE-SU-2024_1548-1
SUSE-SU-2024_1803-1
SUSE-SU-2024_1806-1
SUSE-SU-2024_1831-1
SUSE-SU-2024_1832-1
SUSE-SU-2024_2067-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Flatpak
Red Hat
Red Os
Rocky Linux
Suse
Bwrap
Xdg-Desktop-Portal