PT-2024-5878 · Flatpak+12 · Flatpak+12

Chrisawi

·

Published

2024-08-14

·

Updated

2025-11-19

·

CVE-2024-42472

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Flatpak versions prior to 1.14.0 and 1.15.10
Description The issue is related to how Flatpak handles persistent directories, allowing a malicious or compromised Flatpak app to access and write files outside of its intended sandbox. This is achieved when the persistent=subdir option is used in the application permissions, creating a bind mount that can be exploited if the source directory is replaced with a symlink. The vulnerability can be partially mitigated by patching Flatpak using specific commits, but a complete fix requires updating or patching the version of bubblewrap used by Flatpak to add a new option and then patching Flatpak to use it.
Recommendations For versions prior to 1.14.0 and 1.15.10, update to Flatpak 1.14.10 or 1.15.10, which include the necessary patches for bubblewrap. If Flatpak has been configured at build-time with -Dsystem bubblewrap=bwrap or a similar option, patch the system copy of bubblewrap, typically /usr/bin/bwrap. If Flatpak has been configured at build-time with -Dsystem bubblewrap= or without system bubblewrap, patch the bundled version of bubblewrap, typically /usr/libexec/flatpak-bwrap. As a temporary workaround, avoid using applications that utilize the persistent (--persist) permission.

Exploit

Fix

Special Elements Injection

Weakness Enumeration

Related Identifiers

ALSA-2024:6356
ALSA-2024:6422
ALSA-2024:9449
ALSA-2024_6356
ALSA-2024_6422
ALSA-2024_9449
ALT-PU-2024-11216
BDU:2024-06671
CESA-2024_6422
CVE-2024-42472
DLA-4099-1
DSA-5749-1
GHSA-7HGV-F2J8-XW87
INFSA-2024_6356
INFSA-2024_6422
INFSA-2024_9449
MGASA-2025-0303
OESA-2024-2053
OPENSUSE-SU-2024:14269-1
OPENSUSE-SU-2024:14275-1
OPENSUSE-SU-2024_3104-1
OPENSUSE-SU-2024_3174-1
RHSA-2024:6355
RHSA-2024:6356
RHSA-2024:6357
RHSA-2024:6417
RHSA-2024:6418
RHSA-2024:6419
RHSA-2024:6420
RHSA-2024:6421
RHSA-2024:6422
RHSA-2024:9449
RHSA-2024_6356
RHSA-2024_6422
RHSA-2024_9449
RLSA-2024:6422
RLSA-2024:9449
ROSA-SA-2024-2508
SUSE-RU-2025:0145-1
SUSE-SU-2024:3073-1
SUSE-SU-2024:3104-1
SUSE-SU-2024:3174-1
SUSE-SU-2024_3073-1
SUSE-SU-2024_3104-1
SUSE-SU-2024_3174-1
USN-7046-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Flatpak
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Bubblewrap