A vulnerability has been discovered in Firejail which could result in local root privilege escalation.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202305-19 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Firejail: Local Privilege Escalation Date: May 03, 2023 Bugs: #850748 ID: 202305-19 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability has been discovered in Firejail which could result in local root privilege escalation. Background ========= A SUID program that reduces the risk of security breaches by restricting the running environment of untrusted applications using Linux namespaces and seccomp-bpf. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- Traceback (most recent call last): File "/usr/local/lib/python3.9/site-packages/glsamaker/models/glsa.py", line 326, in generate_mail_table return self._generate_mail_table() File "/usr/local/lib/python3.9/site-packages/glsamaker/models/glsa.py", line 297, in _generate_mail_table vuln.range_types_rev[vuln.pkg_range], vuln.version KeyError: None Description ========== Firejail does not sufficiently validate the user's environment prior to using it as the root user when using the --join command line option. Impact ===== An unprivileged user can exploit this vulnerability to achieve local root privileges. Workaround ========= System administrators can mitigate this vulnerability via adding either "force-nonewprivs yes" or "join no" to the Firejail configuration file in/etc/firejail/firejail.config. Resolution ========= Gentoo has discontinued support for sys-apps/firejail-lts. Users should unmerge it in favor of sys-apps/firejail: # emerge --ask --depclean --verbose "sys-apps/firejail-lts" # emerge --ask --verbose "sys-apps/firejail" All Firejail users should upgrade to the latest version: # emerge --ask --oneshot --verbose "> =sys-apps/firejail-0.9.70" References ========= [ 1 ] CVE-2022-31214 https://nvd.nist.gov/vuln/detail/CVE-2022-31214 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202305-19 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
root escalation in --join logic (CVE-2022-31214) References: - https://bugs.mageia.org/show_bug.cgi?id=30528 - https://www.openwall.com/lists/oss-security/2022/06/08/10 . MGASA-2022-0348 - Updated firejail packages fix security vulnerability Publication date: 01 Oct 2022 URL: https://advisories.mageia.org/MGASA-2022-0348.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-31214 root escalation in --join logic (CVE-2022-31214) References: - https://bugs.mageia.org/show_bug.cgi?id=30528 - https://www.openwall.com/lists/oss-security/2022/06/08/10 - https://firejail.wordpress.com/download-2/release-notes/ - - https://lists.fedoraproject.org/archives/list/
- Update to 0.9.70 (rhbz#2042724). - Mitigates CVE-2022-31214 (rhbz#2095070).. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-e8e9b50a33 2022-09-15 01:53:23.999129 --------------------------------------------------------------------------------Name : firejail Product : Fedora 36 Version : 0.9.70 Release : 1.fc36 URL : https://github.com/netblue30/firejail Summary : Linux namespaces sandbox program Description : Firejail is a SUID sandbox program that reduces the risk of security breaches by restricting the running environment of untrusted applications using Linux namespaces. It includes a sandbox profile for Mozilla Firefox. --------------------------------------------------------------------------------Update Information: - Update to 0.9.70 (rhbz#2042724). - Mitigates CVE-2022-31214 (rhbz#2095070). --------------------------------------------------------------------------------ChangeLog: * Tue Sep 6 2022 Maxwell G - 0.9.70-1 - Update to 0.9.70 (rhbz#2042724). - Mitigates CVE-2022-31214 (rhbz#2095070). * Thu Jul 21 2022 Fedora Release Engineering - 0.9.66-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2042724 - firejail-0.9.70 is available https://bugzilla.redhat.com/show_bug.cgi?id=2042724 [ 2 ] Bug #2095070 - CVE-2022-31214 firejail: CVE-2022-31214: local root exploit reachable via --join logic [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2095070 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-e8e9b50a33' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed withthe Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
- Update to 0.9.70 (rhbz#2042724). - Mitigates CVE-2022-31214 (rhbz#2095070).. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-827d9ce8ac 2022-09-15 01:28:27.969719 --------------------------------------------------------------------------------Name : firejail Product : Fedora 35 Version : 0.9.70 Release : 1.fc35 URL : https://github.com/netblue30/firejail Summary : Linux namespaces sandbox program Description : Firejail is a SUID sandbox program that reduces the risk of security breaches by restricting the running environment of untrusted applications using Linux namespaces. It includes a sandbox profile for Mozilla Firefox. --------------------------------------------------------------------------------Update Information: - Update to 0.9.70 (rhbz#2042724). - Mitigates CVE-2022-31214 (rhbz#2095070). --------------------------------------------------------------------------------ChangeLog: * Tue Sep 6 2022 Maxwell G - 0.9.70-1 - Update to 0.9.70 (rhbz#2042724). - Mitigates CVE-2022-31214 (rhbz#2095070). * Thu Jul 21 2022 Fedora Release Engineering - 0.9.66-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild * Thu Jan 20 2022 Fedora Release Engineering - 0.9.66-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2042724 - firejail-0.9.70 is available https://bugzilla.redhat.com/show_bug.cgi?id=2042724 [ 2 ] Bug #2095070 - CVE-2022-31214 firejail: CVE-2022-31214: local root exploit reachable via --join logic [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2095070 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-827d9ce8ac' at the command line. For more information,refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
- Update to 0.9.70 (rhbz#2042724). - Mitigates CVE-2022-31214 (rhbz#2095070).. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-7ecd36b131 2022-09-14 00:18:15.239093 --------------------------------------------------------------------------------Name : firejail Product : Fedora 37 Version : 0.9.70 Release : 1.fc37 URL : https://github.com/netblue30/firejail Summary : Linux namespaces sandbox program Description : Firejail is a SUID sandbox program that reduces the risk of security breaches by restricting the running environment of untrusted applications using Linux namespaces. It includes a sandbox profile for Mozilla Firefox. --------------------------------------------------------------------------------Update Information: - Update to 0.9.70 (rhbz#2042724). - Mitigates CVE-2022-31214 (rhbz#2095070). --------------------------------------------------------------------------------ChangeLog: * Tue Sep 6 2022 Maxwell G - 0.9.70-1 - Update to 0.9.70 (rhbz#2042724). - Mitigates CVE-2022-31214 (rhbz#2095070). --------------------------------------------------------------------------------References: [ 1 ] Bug #2042724 - firejail-0.9.70 is available https://bugzilla.redhat.com/show_bug.cgi?id=2042724 [ 2 ] Bug #2095070 - CVE-2022-31214 firejail: CVE-2022-31214: local root exploit reachable via --join logic [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2095070 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-7ecd36b131' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Matthias Gerstner discovered that the --join option of Firejail, a sandbox to restrict an application environment, was susceptible to local privilege escalation to root. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3061-1
Matthias Gerstner discovered that the --join option of Firejail, a sandbox to restrict an application environment, was susceptible to local privilege escalation to root. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5167-1
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for firejail ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:10015-1 Rating: important References: #1199148 Cross-References: CVE-2022-31214 CVSS scores: CVE-2022-31214 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for firejail fixes the following issues: firejail was updated to version 0.9.70: -CVE-2022-31214: - root escalation in --join logic (boo#1199148) Reported by Matthias Gerstner, working exploit code was provided to our development team. In the same time frame, the problem was independently reported by Birk Blechschmidt. Full working exploit code was also provided. - feature: enable shell tab completion with --tab (#4936) - feature: disable user profiles at compile time (#4990) - feature: Allow resolution of .local names with avahi-daemon in the apparmor - profile (#5088) - feature: always log seccomp errors (#5110) - feature: firecfg --guide, guided user configuration (#5111) - feature: --oom, kernel OutOfMemory-killer (#5122) - modif: --ids feature needs to be enabled at compile time (#5155) - modif: --nettrace only available to root user - rework: whitelist restructuring (#4985) - rework: firemon, speed up and lots of fixes - bugfix: --private-cwd not expanding macros, broken hyperrogue (#4910) - bugfix: nogroups + wrc prints confusing messages (#4930 #4933) - bugfix: openSUSE Leap - whitelist-run-common.inc (#4954) - bugfix: fix printing in evince (#5011) - bugfix: gcov: fix gcov functions always declared as dummy (#5028) - bugfix: Stop warning on safesupplementary group clean (#5114) - build: remove ultimately unused INSTALL and RANLIB check macros (#5133) - build: mkdeb.sh.in: pass remaining arguments to ./configure (#5154) - ci: replace centos (EOL) with almalinux (#4912) - ci: fix --version not printing compile-time features (#5147) - ci: print version after install & fix apparmor support on build_apparmor (#5148) - docs: Refer to firejail.config in configuration files (#4916) - docs: firejail.config: add warning about allow-tray (#4946) - docs: mention that the protocol command accumulates (#5043) - docs: mention inconsistent homedir bug involving --private=dir (#5052) - docs: mention capabilities(7) on --caps (#5078) - new profiles: onionshare, onionshare-cli, opera-developer, songrec - new profiles: node-gyp, npx, semver, ping-hardened - removed profiles: nvm Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP3: zypper in -t patch openSUSE-2022-10015=1 Package List: - openSUSE Backports SLE-15-SP3 (aarch64 i586 ppc64le s390x x86_64): firejail-0.9.70-bp153.2.6.1 References: https://www.suse.com/security/cve/CVE-2022-31214.html https://bugzilla.suse.com/1199148 . This significant release for Fedora addresses a privilege escalation vulnerability in firejail and enhances overall security measures.. openSUSE security update, firejail patch, root escalation fix, security improvements. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.