Search CVE reports
1 – 10 of 36 results
Flatpak's process ID namespace separation does not prevent a sandboxed app's kill(0, signal) or killpg(0, signal) calls from reaching processes outside the sandbox that share the same process group. A malicious or compromised...
1 affected package
flatpak
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| flatpak | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Flatpak passes through arbitrary vendor-extension keys unmodified when exporting an application's Desktop Entry (.desktop) and D-Bus Service (.service) files, instead of validating against an allowlist. A malicious Flatpak app can...
1 affected package
flatpak
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| flatpak | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Flatpak creates temporary child repository directories under the user cache with world-writable permissions (0777). On multi-user systems with a permissive umask, other local users could read or modify the temporary directory used...
1 affected package
flatpak
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| flatpak | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Flatpak writes the OCI repository authentication token with world-readable permissions (0644) in the system-helper's cache directory, allowing other local users on a multi-user system to read the token and impersonate...
1 affected package
flatpak
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| flatpak | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
A path traversal vulnerability in Flatpak's handling of the files/etc directory during app deployment allows a malicious Flatpak app to cause certain host system files (such as passwd, group, machine-id, or resolv.conf) to be...
1 affected package
flatpak
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| flatpak | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
A path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a malicious Flatpak app to cause deletion of attacker-chosen files outside the deployment directory when the app is...
1 affected package
flatpak
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| flatpak | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
In Flatpak before 1.18.1, the revokefs writer, used by the flatpak-system-helper to receive repository data from unprivileged callers, validated file paths by rejecting literal .. components but did not prevent symlink traversal....
1 affected package
flatpak
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| flatpak | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
In Flatpak before 1.18.1, a malicious sandboxed app can replace ~/.var/app/$appid/.ld.so with a symlink, causing regenerate_ld_cache to write files at an arbitrary location. The filenames and content are not attacker controlled,...
1 affected package
flatpak
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| flatpak | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
security update
1 affected package
flatpak
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| flatpak | Not affected | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
security update
1 affected package
flatpak
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| flatpak | Not affected | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |