Privilege escalation in Flatpak - CVE-2019-8308
Published: February 16, 2019
Vulnerability details
The vulnerability allows an adjacent attacker to escalate privileges on the system.
The vulnerability exists due an error when handling file descriptors related to /proc/self/exe. An adjacent attacker can trick the victim with root privileges into installing a system-wide Flatpak application that has an apply_extra script, and then run the apply_extra script in a sandbox with /proc mounted to escape sandbox protections and maliciously modify executable files as root on the host system.
Affected software
flatpak (Debian package)
flatpak-runtime
flatpak
flatpak-debuginfo
flatpak-debugsource
flatpak-devel
flatpak-help
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
Opensuse
openEuler
Fedora
How to mitigate CVE-2019-8308
flatpak (Debian package) - update to 0.8.9-0+deb9u2
flatpak-runtime - update to f29-2920190117185057.1
flatpak - update to 1.0.3-5
flatpak-debuginfo - update to 1.0.3-5
flatpak-debugsource - update to 1.0.3-5
flatpak-devel - update to 1.0.3-5
flatpak-help - update to 1.0.3-5
flatpak - addressed in versions 1.0.7-1.fc28, 1.2.3-1.fc29