Back

HIGH

flatpak: potential /proc based sandbox escape

Published Feb 12, 2019

Description

Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side executable file.

Affected products

Remediation

Red Hat statement

This flaw appears to impact systems in special cases involving installing flatpak applications and runtimes system-wide. Installation of flatpak applications and runtimes locally should not be impacted.

Metrics

Weaknesses (2)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 12, 2019
Updated Aug 4, 2024
Reserved Feb 12, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Feb 11, 2019