SB2024041902 - Sandbox escape in Flatpak
Published: April 19, 2024 Updated: April 30, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Neutralization of Argument Delimiters in a Command (CVE-ID: CVE-2024-32462)
The vulnerability allows a local application to bypass implemented security restrictions.
The vulnerability exists due to improper input validation when handling CLI arguments in the RequestBackground portal. A malicious application can escape sandbox via a specially crafted arguments and execute arbitrary code on the system.
Remediation
Install update from vendor's website.
References
- https://github.com/flatpak/flatpak/security/advisories/GHSA-phv6-cpc2-2fgj
- https://github.com/flatpak/flatpak/commit/72016e3fce8fcbeab707daf4f1a02b931fcc004d
- https://github.com/flatpak/flatpak/commit/81abe2a37d363f5099c3d0bdcd0caad6efc5bf97
- https://github.com/flatpak/flatpak/commit/b7c1a558e58aaeb1d007d29529bbb270dc4ff11e
- https://github.com/flatpak/flatpak/commit/bbab7ed1e672356d1a78b422462b210e8e875931
- https://github.com/flatpak/flatpak/releases/tag/1.14.6
- https://github.com/flatpak/flatpak/releases/tag/1.15.8
- https://github.com/flatpak/flatpak/releases/tag/1.12.9
- https://github.com/flatpak/flatpak/releases/tag/1.10.9