CVE-2019-8308: High severity suse flatpak vulnerability
A flaw was discovered that may allow an attacker to escape from the flatpak sandbox via /proc/self/exe.
Upstream Commit: https://github.com/flatpak/flatpak/commit/cd2142888fc4c199723a0dfca1f15ea8788a5483
Other sources
Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the applyextra script sandbox, which allows attackers to modify a host-side executable file.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-8308?
CVE-2019-8308 is a vulnerability in Flatpak before version 1.0.7 and 1.1.x and 1.2.x before 1.2.3.
How does CVE-2019-8308 affect Flatpak?
CVE-2019-8308 exposes /proc in the apply_extra script sandbox of Flatpak, allowing attackers to modify a host-side executable file.
What is the severity of CVE-2019-8308?
The severity of CVE-2019-8308 is critical with a CVSS score of 8.2.
How can I fix CVE-2019-8308?
To fix CVE-2019-8308, update your Flatpak installation to version 1.2.3 or apply the appropriate remedy provided by your distribution or package manager.
Where can I find more information about CVE-2019-8308?
You can find more information about CVE-2019-8308 on the Debian Security Tracker, Flatpak mailing list, and the Flatpak GitHub page.