Privilege escalation in Flatpak - CVE-2019-8308

 

Privilege escalation in Flatpak - CVE-2019-8308

Published: February 16, 2019


Vulnerability identifier: #VU17726
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/U:Clear
CVE-ID: CVE-2019-8308
CWE-ID: CWE-264
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vendor: Flatpak
Affected software:
Flatpak

Detailed vulnerability description

The vulnerability allows an adjacent attacker to escalate privileges on the system.

The vulnerability exists due an error when handling file descriptors related to /proc/self/exe. An adjacent attacker can trick the victim with root privileges into installing a system-wide Flatpak application that has an apply_extra script, and then run the apply_extra script in a sandbox with /proc mounted to escape sandbox protections and maliciously modify executable files as root on the host system.


How to mitigate CVE-2019-8308

The vulnerability has been addressed in the versions 1.0.7, 1.2.3.

Sources