Input validation error in Bubblewrap - CVE-2017-5226
Published: March 20, 2023
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient validation of user-supplied input. The non-privileged session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the sandbox.
Affected software
Flatpak
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM System z (Structure A)
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for ARM 64
Fedora
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux for x86_64
Anolis OS
openEuler
bubblewrap
flatpak (Red Hat package)
flatpak
flatpak-debuginfo
flatpak-devel
flatpak-debugsource
flatpak-help
flatpak-libs
flatpak-session-helper
flatpak-selinux
How to mitigate CVE-2017-5226
Flatpak - addressed in versions 1.2.4, 1.3.1
bubblewrap - update to 0.1.7-1.el7
flatpak (Red Hat package) - addressed in versions 1.0.2-5.el7_6, 1.0.6-3.el8_0
flatpak - addressed in versions 1.0.3-6, 1.10.2-7
flatpak-debuginfo - addressed in versions 1.0.3-6, 1.10.2-7
flatpak-devel - addressed in versions 1.0.3-6, 1.10.2-7
flatpak-debugsource - addressed in versions 1.0.3-6, 1.10.2-7
flatpak-help - addressed in versions 1.0.3-6, 1.10.2-7
flatpak - update to 1.10.8-1.0.1
flatpak-devel - update to 1.10.8-1.0.1
flatpak-libs - update to 1.10.8-1.0.1
flatpak-session-helper - update to 1.10.8-1.0.1
flatpak-selinux - update to 1.10.8-1.0.1
External References
- https://github.com/projectatomic/bubblewrap/issues/142
- https://github.com/projectatomic/bubblewrap/commit/d7fc532c42f0e9bf427923bab85433282b3e5117
- https://bugzilla.redhat.com/show_bug.cgi?id=1411811
- http://www.securityfocus.com/bid/97260
- http://www.openwall.com/lists/oss-security/2020/07/10/1
- https://www.openwall.com/lists/oss-security/2023/03/14/2
- http://www.openwall.com/lists/oss-security/2023/03/17/1
Related Security Bulletins
- Security restrictions bypass in Bubblewrap
- Multiple vulnerabilities in flatpak
- openEuler update for flatpak
- openEuler 22.03 LTS SP3 update for flatpak
- openEuler 22.03 LTS update for flatpak
- openEuler 22.03 LTS SP1 update for flatpak
- openEuler 22.03 LTS SP2 update for flatpak
- Anolis OS update for flatpak
- Fedora EPEL 7 update for bubblewrap
- Red Hat Enterprise Linux 7 update for flatpak
- Red Hat Enterprise Linux 8 update for flatpak