- -------------------------------------------------------------------------
Debian Security Advisory DSA-5749-1                   security@debian.org
https://www.debian.org/security/                     Salvatore Bonaccorso
August 14, 2024                       https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : flatpak
CVE ID         : CVE-2024-42472

Chris Williams discovered a flaw in the handling of mounts for
persistent directories in Flatpak, an application deployment framework
for desktop apps. A malicious or compromised Flatpak app using
persistent directories could take advantage of this flaw to access files
outside of the sandbox.

Details can be found in the upstream advisory at
https://github.com/flatpak/flatpak/security/advisories/GHSA-7hgv-f2j8-xw87

For the stable distribution (bookworm), this problem has been fixed in
version 1.14.10-1~deb12u1. To address the vulnerability, flatpak uses a
new feature provided in bubblewrap and provided in version
0.8.0-2+deb12u1 along with this update.

We recommend that you upgrade your flatpak packages.

For the detailed security status of flatpak please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/flatpak

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org

Debian: DSA-5749-1: flatpak Security Advisory Updates

August 14, 2024
Chris Williams discovered a flaw in the handling of mounts for persistent directories in Flatpak, an application deployment framework for desktop apps

Summary

Details can be found in the upstream advisory at
https://github.com/flatpak/flatpak/security/advisories/GHSA-7hgv-f2j8-xw87

For the stable distribution (bookworm), this problem has been fixed in
version 1.14.10-1~deb12u1. To address the vulnerability, flatpak uses a
new feature provided in bubblewrap and provided in version
0.8.0-2+deb12u1 along with this update.

We recommend that you upgrade your flatpak packages.

For the detailed security status of flatpak please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/flatpak

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
Package : flatpak
CVE ID : CVE-2024-42472

Related News