REDHAT-BUG-2542683: Low severity Flatpak Flatpak vulnerability
GHSA-v64f-hrwr-j4vh (https://github.com/flatpak/flatpak/security/advisories/GHSA-v64f-hrwr-j4vh)
Description: A malicious Flatpak application can influence host system behavior beyond its sandbox by including arbitrary keys in its exported Desktop Entry (.desktop) or D-Bus Service (.service) files. This can lead to denial of service (e.g. X-GNOME-AutoRestart causing unconditional application restarts) or unintended interaction with host services (e.g. SystemdService directing the D-Bus daemon to activate a host systemd unit instead of the sandboxed wrapper). When Flatpak exports these files, it rewrites Exec= to go through the flatpak run wrapper and removes a small denylist of known-dangerous keys, but passes all other keys through unmodified. The fix switches from a denylist to an allowlist, exporting only keys from a curated list of known-safe entries.
Mitigation: Only install applications from trusted sources. Patched in 1.18.4 by commit 33931025 ("dir: Validate Desktop Entry and D-Bus Service"). Credit: Reported by Markus Göllnitz.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Flatpakto a version that resolves this vulnerability.Fixed in 1.18.4Patch 33931025 - Compensating control
Only install Flatpak applications from trusted sources.
Event History
Frequently Asked Questions
What does an attacker need to control to exploit this issue?
The attacker needs to provide a malicious Flatpak application containing arbitrary keys in exported Desktop Entry (.desktop) or D-Bus Service (.service) files.
What is the recommended mitigation if an update cannot be applied immediately?
Only install Flatpak applications from trusted sources.
Which version includes the fix?
The issue is patched in Flatpak 1.18.4. The fix validates exported Desktop Entry and D-Bus Service files using an allowlist of known-safe entries.