This update for firejail fixes the following issues:
firejail 0.9.64.4 is shipped to openSUSE Leap 15.2
- CVE-2021-26910: Fixed root privilege escalation due to race condition
(boo#1181990)
Update to 0.9.64.4:
* disabled overlayfs, pending multiple fixes
* fixed launch firefox for open url in telegram-desktop.profile
Update to 0.9.64.2:
* allow --tmpfs inside $HOME for unprivileged users * --disable-usertmpfs compile time option
* allow AF_BLUETOOTH via --protocol=bluetooth
* setup guide for new users: contrib/firejail-welcome.sh
* implement netns in profiles
* added nolocal6.net IPv6 network filter
* new profiles: spectacle, chromium-browser-privacy, gtk-straw-viewer,
gtk-youtube-viewer, gtk2-youtube-viewer, gtk3-youtube-viewer,
straw-viewer, lutris, dolphin-emu, authenticator-rs, servo, npm, marker,
yarn, lsar, unar, agetpkg, mdr, shotwell, qnapi, new profiles: guvcview,
pkglog, kdiff3, CoyIM.
Update to...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.2:
zypper in -t patch openSUSE-2021-271=1
- openSUSE Leap 15.2 (x86_64):
firejail-0.9.64.4-lp152.3.6.1
firejail-debuginfo-0.9.64.4-lp152.3.6.1
firejail-debugsource-0.9.64.4-lp152.3.6.1
https://www.suse.com/security/cve/CVE-2020-17367.html
https://www.suse.com/security/cve/CVE-2020-17368.html
https://www.suse.com/security/cve/CVE-2021-26910.html
https://bugzilla.suse.com/1181990
Get the latest Linux and open source security news straight to your inbox.