Privilege escalation in Flatpak - CVE-2019-8308

 

Privilege escalation in Flatpak - CVE-2019-8308

Published: February 16, 2019


Vulnerability identifier: #VU17726
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-8308
CWE-ID: CWE-264
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an adjacent attacker to escalate privileges on the system.

The vulnerability exists due an error when handling file descriptors related to /proc/self/exe. An adjacent attacker can trick the victim with root privileges into installing a system-wide Flatpak application that has an apply_extra script, and then run the apply_extra script in a sandbox with /proc mounted to escape sandbox protections and maliciously modify executable files as root on the host system.


Affected software

Flatpak
flatpak (Debian package)
flatpak-runtime
flatpak
flatpak-debuginfo
flatpak-debugsource
flatpak-devel
flatpak-help
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
Opensuse
openEuler
Fedora

How to mitigate CVE-2019-8308

The vulnerability has been addressed in the versions 1.0.7, 1.2.3.

Flatpak - addressed in versions 1.0.7, 1.2.3
flatpak (Debian package) - update to 0.8.9-0+deb9u2
flatpak-runtime - update to f29-2920190117185057.1
flatpak - update to 1.0.3-5
flatpak-debuginfo - update to 1.0.3-5
flatpak-debugsource - update to 1.0.3-5
flatpak-devel - update to 1.0.3-5
flatpak-help - update to 1.0.3-5
flatpak - addressed in versions 1.0.7-1.fc28, 1.2.3-1.fc29

External References

Related Security Bulletins