REDHAT-BUG-2539417: Medium severity Flatpak Flatpak vulnerability
GHSA-9rww-v4mm-x4jg (https://github.com/flatpak/flatpak/security/advisories/GHSA-9rww-v4mm-x4jg)
Description: When extracting OCI layer archives, Flatpak rebases archive entry pathnames to the destination directory using gbuildfilename, and sets ARCHIVEEXTRACTSECURENODOTDOT to reject .. components in both pathnames and hardlink targets. However, hardlink targets were not rebased to the destination directory. A crafted archive entry with an absolute hardlink target (e.g. /etc/shadow) causes libarchive to call link() with that path directly, hardlinking the host file into the extraction directory and making its contents readable. An attacker controlling an OCI registry can serve a crafted layer archive that exploits this during flatpak install or flatpak update.
Mitigation: Only install applications from trusted OCI registries. Flatpak remotes using the default OSTree transport are not affected. Versions 1.16.x and older are not believed to be vulnerable (introduced in 1.17.0). Fixed in 1.18.1. Reported by @swick.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Flatpakto a version that resolves this vulnerability.Fixed in 1.18.1 - Compensating control
Only install applications from trusted OCI registries.
Event History
Frequently Asked Questions
Which Flatpak installations are exposed to this issue?
Installations using OCI-based Flatpak remotes may be exposed if they run a vulnerable version. Remotes using Flatpak's default OSTree transport are not affected, and versions 1.16.x and older are not believed to be vulnerable.
What does an attacker need to exploit this?
The attacker must control an OCI registry used by the target system and serve a crafted OCI layer archive. Exploitation occurs during a flatpak install or flatpak update from that registry.
What can be done if updating Flatpak is not immediately possible?
Install applications only from trusted OCI registries. Avoid installing or updating from OCI registries that could be attacker-controlled; default OSTree-based remotes are not affected.
How can I determine whether I may already be affected?
Check whether the system uses OCI-based Flatpak remotes and whether it runs Flatpak 1.17.0 or later before the fix in 1.18.1. The issue can cause host files referenced by crafted absolute hardlink targets to be linked into the extraction directory and made readable.