REDHAT-BUG-2542235: High severity Flatpak xdg-dbus-proxy vulnerability
An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages.
xdg-dbus-proxy was designed to be part of the sandbox boundary for Flatpak, but it is released as a separate project and is sometimes used by other app frameworks such as Firejail.
Impact: A malicious or compromised Flatpak app could achieve arbitrary code execution outside its sandbox. If other app frameworks rely on xdg-dbus-proxy in the same way that Flatpak does, then they will have an equivalent vulnerability until xdg-dbus-proxy is updated.
Fixed in 0.1.9 by commits: e5702fca4dba9600721921fbca2dbc39dc5ca400 "proxy: Don't assume that only returns and errors have a reply-serial" fc027f759316fb2a6c45648200b6f100202eb84e "proxy: Make it clearer which direction messages are going in" e4465a0dfe96da3b39929a30a1ac3a22b16223e3 "proxy: Only allow replies to go to the correct destination"
Reported by @refi64.
Reference: https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-2cgv-pwcq-wvpq
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
xdg-dbus-proxyto a version that resolves this vulnerability.Fixed in 0.1.9
Event History
Frequently Asked Questions
Which environments are exposed to this issue?
Flatpak environments using xdg-dbus-proxy before 0.1.9 are exposed because the proxy is part of Flatpak's sandbox boundary. Other application frameworks, including Firejail where it relies on xdg-dbus-proxy in the same way, can have an equivalent issue until the proxy is updated.
What must an attacker control to exploit the vulnerability?
The attacker needs control of a malicious or compromised sandboxed application that can send messages through xdg-dbus-proxy to the D-Bus session bus. Exploitation involves setting a reply serial number on a message that is not a reply, bypassing intended message filtering.
What is the potential impact for a compromised Flatpak application?
A malicious or compromised Flatpak app could achieve arbitrary code execution outside of its sandbox. This defeats the intended isolation provided by the sandbox boundary.
What remediation is identified?
Update xdg-dbus-proxy to version 0.1.9 or later. The issue was fixed in 0.1.9 with changes that prevent assumptions about reply serials and restrict replies to their correct destination.