REDHAT-BUG-2539421: Medium severity Flatpak Flatpak vulnerability
GHSA-q4gr-vc25-57m5 (https://github.com/flatpak/flatpak/security/advisories/GHSA-q4gr-vc25-57m5)
Description: By using the system helper's unprivileged RemoveLocalRef method, an attacker was able to remove the remote ref of the app or runtime. The anti-downgrade check would fail to find the remote ref, and with it the date to check against, allowing an attacker to bypass the check and downgrade apps.
Mitigation: Ensure that Flatpak apps installed system-wide are fully updated before running them. Fixed in 1.18.1 (backports available for 1.16.x). Discovered and reported by BreachX Zero Day Labs, using Typhon AI Mil v2. Contributing Researcher: Vivek Parikh.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Flatpakto a version that resolves this vulnerability.Fixed in 1.18.1Patch GHSA-q4gr-vc25-57m5 - Compensating control
Ensure that Flatpak apps installed system-wide are fully updated before running them.
Event History
Frequently Asked Questions
What access does an attacker need to bypass the anti-downgrade protection?
The attacker needs to be able to use the system helper's unprivileged RemoveLocalRef method to remove a remote ref for an app or runtime. Removing that ref prevents the anti-downgrade check from finding the date it uses for comparison.
Which installations should be prioritized for mitigation?
System-wide Flatpak installations should be prioritized. Ensure all system-wide installed Flatpak apps are fully updated before they are run.
What fixed versions are identified?
The issue is fixed in Flatpak 1.18.1. Backports are available for the 1.16.x series.