REDHAT-BUG-2539424: Low severity Flatpak Flatpak vulnerability
GHSA-89xm-3m96-w3jg (https://github.com/flatpak/flatpak/security/advisories/GHSA-89xm-3m96-w3jg)
Description: By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull does not get cancelled but removed from internal tracking, making it impossible to stop it.
Mitigation: No known mitigation other than updating. Patched in 1.16.4 and 1.18.0. Credit: Asim Viladi Oglu Manizada.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
flatpakto a version that resolves this vulnerability.Fixed in 1.16.4 - Upgrade
Upgrade
flatpakto a version that resolves this vulnerability.Fixed in 1.18.0
Event History
Frequently Asked Questions
What access or conditions are required to trigger this issue?
An attacker must be able to call org.freedesktop.Flatpak.SystemHelper.CancelPull against a pull initiated by another user.
What is the operational impact if exploitation occurs?
The other user's pull is removed from Flatpak's internal tracking without being cancelled, leaving the pull impossible to stop through normal tracking.
What versions contain fixes, and is there a workaround?
The issue is patched in Flatpak 1.16.4 and 1.18.0. No mitigation other than updating is known.