UNIX symbolic link following in Flatpak - CVE-2024-42472
Published: August 15, 2024
Vulnerability identifier: #VU96049
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-42472
CWE-ID: CWE-61
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a symlink following issue when mounting persistent directories. A local user can create a specially crafted symbolic link and escape sandbox.
Affected software
Flatpak
Oracle Linux
SUSE Linux Enterprise Server 15 SP5
Gentoo Linux
Debian Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Anolis OS
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Basesystem Module
Desktop Applications Module
openSUSE Leap
openEuler
Ubuntu
Fedora
Bubblewrap
Red Hat OpenShift Dev Spaces
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
bubblewrap
bubblewrap-debuginfo
bubblewrap-debugsource
bubblewrap (Ubuntu package)
bubblewrap (Red Hat package)
bubblewrap-zsh-completion
flatpak-builder
flatpak-libs
flatpak
flatpak-devel
flatpak (Red Hat package)
flatpak-debuginfo
libflatpak0-debuginfo
flatpak-debugsource
typelib-1_0-Flatpak-1_0
libflatpak0
sys-apps/flatpak
flatpak (Ubuntu package)
libflatpak0 (Ubuntu package)
flatpak-help
flatpak-zsh-completion
system-user-flatpak
flatpak-selinux
flatpak-session-helper
flatpak (Debian package)
flatpak-remote-flathub
flatpak-doc
flatpak-tests
wayland-protocols-devel
Juniper Junos Space
OpenShift API for Data Protection (OADP)
watsonx Assistant for IBM Cloud Pak for Data
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
IBM Qradar SIEM
Oracle Linux
SUSE Linux Enterprise Server 15 SP5
Gentoo Linux
Debian Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Anolis OS
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Basesystem Module
Desktop Applications Module
openSUSE Leap
openEuler
Ubuntu
Fedora
Bubblewrap
Red Hat OpenShift Dev Spaces
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
bubblewrap
bubblewrap-debuginfo
bubblewrap-debugsource
bubblewrap (Ubuntu package)
bubblewrap (Red Hat package)
bubblewrap-zsh-completion
flatpak-builder
flatpak-libs
flatpak
flatpak-devel
flatpak (Red Hat package)
flatpak-debuginfo
libflatpak0-debuginfo
flatpak-debugsource
typelib-1_0-Flatpak-1_0
libflatpak0
sys-apps/flatpak
flatpak (Ubuntu package)
libflatpak0 (Ubuntu package)
flatpak-help
flatpak-zsh-completion
system-user-flatpak
flatpak-selinux
flatpak-session-helper
flatpak (Debian package)
flatpak-remote-flathub
flatpak-doc
flatpak-tests
wayland-protocols-devel
Juniper Junos Space
OpenShift API for Data Protection (OADP)
watsonx Assistant for IBM Cloud Pak for Data
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
IBM Qradar SIEM
How to mitigate CVE-2024-42472
Install updates from vendor's website.
Flatpak - addressed in versions 1.14.10, 1.15.10
Bubblewrap - addressed in versions 0.6.3, 0.10.0
Juniper Junos Space - update to 24.1R3
bubblewrap - addressed in versions 0.3.3-3.3.1, 0.4.1-150200.3.3.1, 0.11.0-150500.3.9.1
bubblewrap-debuginfo - addressed in versions 0.3.3-3.3.1, 0.4.1-150200.3.3.1, 0.11.0-150500.3.9.1
bubblewrap-debugsource - addressed in versions 0.3.3-3.3.1, 0.4.1-150200.3.3.1, 0.11.0-150500.3.9.1
bubblewrap (Ubuntu package) - addressed in versions 0.4.0-1ubuntu4.1, 0.6.1-1ubuntu0.1, 0.9.0-1ubuntu0.1
bubblewrap - update to 0.4.0-2
bubblewrap (Red Hat package) - addressed in versions 0.4.0-2.el8_2, 0.4.0-2.el8_4, 0.4.0-2.el8_6, 0.4.0-2.el8_8, 0.4.0-2.el8_10, 0.4.1-7.el9_0, 0.4.1-7.el9_2, 0.4.1-7.el9_4, 0.4.1-8.el9_5
bubblewrap-zsh-completion - update to 0.11.0-150500.3.9.1
flatpak-builder - update to 1.0.0-15
flatpak-libs - addressed in versions 1.0.9-15, 1.12.9-3, 1.16.4-1
flatpak - addressed in versions 1.0.9-15, 1.12.9-3, 1.16.4-1
flatpak-devel - addressed in versions 1.0.9-15, 1.12.9-3, 1.16.4-1
flatpak (Red Hat package) - addressed in versions 1.0.9-15.el7_9, 1.6.2-9.el8_2, 1.8.5-7.el8_4, 1.8.7-4.el8_6, 1.10.7-4.el8_8, 1.12.5-5.el9_0, 1.12.7-5.el9_2, 1.12.9-3.el8_10, 1.12.9-3.el9_4, 1.12.9-3.el9_5
OpenShift API for Data Protection (OADP) - addressed in versions 1.3.4, 1.4.2
flatpak-debuginfo - addressed in versions 1.4.2-3.9.1, 1.10.8-150200.4.21.1, 1.12.8-150400.3.9.1, 1.16.0-150500.3.15.1, 1.16.0-150600.3.6.1
libflatpak0-debuginfo - addressed in versions 1.4.2-3.9.1, 1.10.8-150200.4.21.1, 1.12.8-150400.3.9.1, 1.16.0-150500.3.15.1, 1.16.0-150600.3.6.1
flatpak-debugsource - addressed in versions 1.4.2-3.9.1, 1.10.8-150200.4.21.1, 1.12.8-150400.3.9.1, 1.16.0-150500.3.15.1, 1.16.0-150600.3.6.1
flatpak - addressed in versions 1.4.2-3.9.1, 1.10.8-150200.4.21.1, 1.12.8-150400.3.9.1, 1.16.0-150500.3.15.1, 1.16.0-150600.3.6.1
typelib-1_0-Flatpak-1_0 - addressed in versions 1.4.2-3.9.1, 1.10.8-150200.4.21.1, 1.12.8-150400.3.9.1, 1.16.0-150500.3.15.1, 1.16.0-150600.3.6.1
libflatpak0 - addressed in versions 1.4.2-3.9.1, 1.10.8-150200.4.21.1, 1.12.8-150400.3.9.1, 1.16.0-150500.3.15.1, 1.16.0-150600.3.6.1
sys-apps/flatpak - update to 1.4.10
flatpak (Ubuntu package) - addressed in versions 1.6.5-0ubuntu0.5, 1.12.7-1ubuntu0.1, 1.14.6-1ubuntu0.1
libflatpak0 (Ubuntu package) - addressed in versions 1.6.5-0ubuntu0.5, 1.12.7-1ubuntu0.1, 1.14.6-1ubuntu0.1
flatpak-help - update to 1.10.2-9
flatpak - update to 1.10.2-9
flatpak-debuginfo - update to 1.10.2-9
flatpak-debugsource - update to 1.10.2-9
flatpak-devel - update to 1.10.2-9
flatpak-zsh-completion - addressed in versions 1.10.8-150200.4.21.1, 1.12.8-150400.3.9.1, 1.16.0-150500.3.15.1, 1.16.0-150600.3.6.1
flatpak-devel - addressed in versions 1.10.8-150200.4.21.1, 1.12.8-150400.3.9.1, 1.16.0-150500.3.15.1, 1.16.0-150600.3.6.1
system-user-flatpak - addressed in versions 1.10.8-150200.4.21.1, 1.12.8-150400.3.9.1, 1.16.0-150500.3.15.1, 1.16.0-150600.3.6.1
flatpak-selinux - addressed in versions 1.12.9-3, 1.16.4-1
flatpak-session-helper - addressed in versions 1.12.9-3, 1.16.4-1
flatpak (Debian package) - update to 1.14.10-1~deb12u1
flatpak - addressed in versions 1.15.10-1.fc40, 1.15.10-1.fc41
flatpak-remote-flathub - addressed in versions 1.16.0-150500.3.15.1, 1.16.0-150600.3.6.1
flatpak-doc - update to 1.16.4-1
flatpak-tests - update to 1.16.4-1
wayland-protocols-devel - update to 1.36-150500.3.3.1
Red Hat OpenShift Dev Spaces - update to 3.17.0
watsonx Assistant for IBM Cloud Pak for Data - update to 4.8.8
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.1
watsonx Assistant Cartridge - update to 5.1.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF03
Bubblewrap - addressed in versions 0.6.3, 0.10.0
Juniper Junos Space - update to 24.1R3
bubblewrap - addressed in versions 0.3.3-3.3.1, 0.4.1-150200.3.3.1, 0.11.0-150500.3.9.1
bubblewrap-debuginfo - addressed in versions 0.3.3-3.3.1, 0.4.1-150200.3.3.1, 0.11.0-150500.3.9.1
bubblewrap-debugsource - addressed in versions 0.3.3-3.3.1, 0.4.1-150200.3.3.1, 0.11.0-150500.3.9.1
bubblewrap (Ubuntu package) - addressed in versions 0.4.0-1ubuntu4.1, 0.6.1-1ubuntu0.1, 0.9.0-1ubuntu0.1
bubblewrap - update to 0.4.0-2
bubblewrap (Red Hat package) - addressed in versions 0.4.0-2.el8_2, 0.4.0-2.el8_4, 0.4.0-2.el8_6, 0.4.0-2.el8_8, 0.4.0-2.el8_10, 0.4.1-7.el9_0, 0.4.1-7.el9_2, 0.4.1-7.el9_4, 0.4.1-8.el9_5
bubblewrap-zsh-completion - update to 0.11.0-150500.3.9.1
flatpak-builder - update to 1.0.0-15
flatpak-libs - addressed in versions 1.0.9-15, 1.12.9-3, 1.16.4-1
flatpak - addressed in versions 1.0.9-15, 1.12.9-3, 1.16.4-1
flatpak-devel - addressed in versions 1.0.9-15, 1.12.9-3, 1.16.4-1
flatpak (Red Hat package) - addressed in versions 1.0.9-15.el7_9, 1.6.2-9.el8_2, 1.8.5-7.el8_4, 1.8.7-4.el8_6, 1.10.7-4.el8_8, 1.12.5-5.el9_0, 1.12.7-5.el9_2, 1.12.9-3.el8_10, 1.12.9-3.el9_4, 1.12.9-3.el9_5
OpenShift API for Data Protection (OADP) - addressed in versions 1.3.4, 1.4.2
flatpak-debuginfo - addressed in versions 1.4.2-3.9.1, 1.10.8-150200.4.21.1, 1.12.8-150400.3.9.1, 1.16.0-150500.3.15.1, 1.16.0-150600.3.6.1
libflatpak0-debuginfo - addressed in versions 1.4.2-3.9.1, 1.10.8-150200.4.21.1, 1.12.8-150400.3.9.1, 1.16.0-150500.3.15.1, 1.16.0-150600.3.6.1
flatpak-debugsource - addressed in versions 1.4.2-3.9.1, 1.10.8-150200.4.21.1, 1.12.8-150400.3.9.1, 1.16.0-150500.3.15.1, 1.16.0-150600.3.6.1
flatpak - addressed in versions 1.4.2-3.9.1, 1.10.8-150200.4.21.1, 1.12.8-150400.3.9.1, 1.16.0-150500.3.15.1, 1.16.0-150600.3.6.1
typelib-1_0-Flatpak-1_0 - addressed in versions 1.4.2-3.9.1, 1.10.8-150200.4.21.1, 1.12.8-150400.3.9.1, 1.16.0-150500.3.15.1, 1.16.0-150600.3.6.1
libflatpak0 - addressed in versions 1.4.2-3.9.1, 1.10.8-150200.4.21.1, 1.12.8-150400.3.9.1, 1.16.0-150500.3.15.1, 1.16.0-150600.3.6.1
sys-apps/flatpak - update to 1.4.10
flatpak (Ubuntu package) - addressed in versions 1.6.5-0ubuntu0.5, 1.12.7-1ubuntu0.1, 1.14.6-1ubuntu0.1
libflatpak0 (Ubuntu package) - addressed in versions 1.6.5-0ubuntu0.5, 1.12.7-1ubuntu0.1, 1.14.6-1ubuntu0.1
flatpak-help - update to 1.10.2-9
flatpak - update to 1.10.2-9
flatpak-debuginfo - update to 1.10.2-9
flatpak-debugsource - update to 1.10.2-9
flatpak-devel - update to 1.10.2-9
flatpak-zsh-completion - addressed in versions 1.10.8-150200.4.21.1, 1.12.8-150400.3.9.1, 1.16.0-150500.3.15.1, 1.16.0-150600.3.6.1
flatpak-devel - addressed in versions 1.10.8-150200.4.21.1, 1.12.8-150400.3.9.1, 1.16.0-150500.3.15.1, 1.16.0-150600.3.6.1
system-user-flatpak - addressed in versions 1.10.8-150200.4.21.1, 1.12.8-150400.3.9.1, 1.16.0-150500.3.15.1, 1.16.0-150600.3.6.1
flatpak-selinux - addressed in versions 1.12.9-3, 1.16.4-1
flatpak-session-helper - addressed in versions 1.12.9-3, 1.16.4-1
flatpak (Debian package) - update to 1.14.10-1~deb12u1
flatpak - addressed in versions 1.15.10-1.fc40, 1.15.10-1.fc41
flatpak-remote-flathub - addressed in versions 1.16.0-150500.3.15.1, 1.16.0-150600.3.6.1
flatpak-doc - update to 1.16.4-1
flatpak-tests - update to 1.16.4-1
wayland-protocols-devel - update to 1.36-150500.3.3.1
Red Hat OpenShift Dev Spaces - update to 3.17.0
watsonx Assistant for IBM Cloud Pak for Data - update to 4.8.8
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.1
watsonx Assistant Cartridge - update to 5.1.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF03
External References
Related Security Bulletins
- Sandbox escape in Flatpak
- bubblewrap update for Flatpak
- Debian update for flatpak
- openEuler update for flatpak
- Fedora 41 update for flatpak
- Fedora 40 update for flatpak
- SUSE update for bubblewrap and flatpak
- Red Hat Enterprise Linux 7 Extended Lifecycle Support update for flatpak
- Red Hat Enterprise Linux 8 update for bubblewrap and flatpak
- Red Hat Enterprise Linux 8 update for bubblewrap and flatpak
- Red Hat Enterprise Linux 8 update for bubblewrap and flatpak
- Red Hat Enterprise Linux 8 update for bubblewrap and flatpak
- Red Hat Enterprise Linux 8 update for bubblewrap and flatpak
- SUSE update for bubblewrap and flatpak
- Red Hat Enterprise Linux 9 update for bubblewrap and flatpak
- Red Hat Enterprise Linux 9 update for bubblewrap and flatpak
- Red Hat Enterprise Linux 9 update for bubblewrap and flatpak
- Multiple vulnerabilities in IBM QRadar SIEM
- Ubuntu update for bubblewrap
- Multiple vulnerabilities in Oracle Linux
- Gentoo update for Flatpak
- Red Hat Enterprise Linux 9 update for bubblewrap and flatpak
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.3
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.17
- SUSE update for Recommended update for bubblewrap, flatpak, wayland-protocols
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.4
- IBM watsonx Assistant Cartridge and IBM watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component update for Flatpak
- Multiple vulnerabilities in IBM watsonx Assistant for IBM Cloud Pak for Data
- Anolis OS update for flatpak and bubblewrap
- Anolis OS update for flatpak
- Junos Space update for third-party components
- Anolis OS update for flatpak