Input validation error in Bubblewrap - CVE-2017-5226

 

Input validation error in Bubblewrap - CVE-2017-5226

Published: March 20, 2023


Vulnerability identifier: #VU73856
CSH Severity: Medium
CVSS v4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-5226
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient validation of user-supplied input. The non-privileged session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the sandbox.


Affected software

Bubblewrap
Flatpak
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM System z (Structure A)
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for ARM 64
Fedora
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux for x86_64
Anolis OS
openEuler
bubblewrap
flatpak (Red Hat package)
flatpak
flatpak-debuginfo
flatpak-devel
flatpak-debugsource
flatpak-help
flatpak-libs
flatpak-session-helper
flatpak-selinux

How to mitigate CVE-2017-5226

Install updates from vendor's website.

Bubblewrap - update to 0.1.5
Flatpak - addressed in versions 1.2.4, 1.3.1
bubblewrap - update to 0.1.7-1.el7
flatpak (Red Hat package) - addressed in versions 1.0.2-5.el7_6, 1.0.6-3.el8_0
flatpak - addressed in versions 1.0.3-6, 1.10.2-7
flatpak-debuginfo - addressed in versions 1.0.3-6, 1.10.2-7
flatpak-devel - addressed in versions 1.0.3-6, 1.10.2-7
flatpak-debugsource - addressed in versions 1.0.3-6, 1.10.2-7
flatpak-help - addressed in versions 1.0.3-6, 1.10.2-7
flatpak - update to 1.10.8-1.0.1
flatpak-devel - update to 1.10.8-1.0.1
flatpak-libs - update to 1.10.8-1.0.1
flatpak-session-helper - update to 1.10.8-1.0.1
flatpak-selinux - update to 1.10.8-1.0.1

External References

Related Security Bulletins