RHSA-2024:3961: Important: flatpak security update
Important: flatpak security update
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/flatpakto a version that resolves this vulnerability.Fixed in 1.12.9-1.el8_10 - Upgrade
Upgrade
redhat/flatpak-debuginfoto a version that resolves this vulnerability.Fixed in 1.12.9-1.el8_10 - Upgrade
Upgrade
redhat/flatpak-debugsourceto a version that resolves this vulnerability.Fixed in 1.12.9-1.el8_10 - Upgrade
Upgrade
redhat/flatpak-libsto a version that resolves this vulnerability.Fixed in 1.12.9-1.el8_10 - Upgrade
Upgrade
redhat/flatpak-libs-debuginfoto a version that resolves this vulnerability.Fixed in 1.12.9-1.el8_10 - Upgrade
Upgrade
redhat/flatpak-selinuxto a version that resolves this vulnerability.Fixed in 1.12.9-1.el8_10 - Upgrade
Upgrade
redhat/flatpak-session-helperto a version that resolves this vulnerability.Fixed in 1.12.9-1.el8_10 - Upgrade
Upgrade
redhat/flatpak-session-helper-debuginfoto a version that resolves this vulnerability.Fixed in 1.12.9-1.el8_10 - Upgrade
Upgrade
redhat/flatpak-tests-debuginfoto a version that resolves this vulnerability.Fixed in 1.12.9-1.el8_10 - Upgrade
Upgrade
redhat/flatpakto a version that resolves this vulnerability.Fixed in 1.12.9-1.el8_10.aa - Upgrade
Upgrade
redhat/flatpak-debuginfoto a version that resolves this vulnerability.Fixed in 1.12.9-1.el8_10.aa - Upgrade
Upgrade
redhat/flatpak-debugsourceto a version that resolves this vulnerability.Fixed in 1.12.9-1.el8_10.aa - Upgrade
Upgrade
redhat/flatpak-libsto a version that resolves this vulnerability.Fixed in 1.12.9-1.el8_10.aa - Upgrade
Upgrade
redhat/flatpak-libs-debuginfoto a version that resolves this vulnerability.Fixed in 1.12.9-1.el8_10.aa - Upgrade
Upgrade
redhat/flatpak-session-helperto a version that resolves this vulnerability.Fixed in 1.12.9-1.el8_10.aa - Upgrade
Upgrade
redhat/flatpak-session-helper-debuginfoto a version that resolves this vulnerability.Fixed in 1.12.9-1.el8_10.aa - Upgrade
Upgrade
redhat/flatpak-tests-debuginfoto a version that resolves this vulnerability.Fixed in 1.12.9-1.el8_10.aa - Upgrade
Upgrade
redhat/flatpak-develto a version that resolves this vulnerability.Fixed in 1.12.9-1.el8_10 - Upgrade
Upgrade
redhat/flatpak-develto a version that resolves this vulnerability.Fixed in 1.12.9-1.el8_10.aa
Event History
Frequently Asked Questions
What security issue is addressed in RHSA-2024:3961?
RHSA-2024:3961 addresses a sandbox escape vulnerability in flatpak via the RequestBackground portal (CVE-2024-32462).
What is the severity of RHSA-2024:3961?
The severity of RHSA-2024:3961 is classified as important.
How do I fix the vulnerability described in RHSA-2024:3961?
To fix the vulnerability described in RHSA-2024:3961, update flatpak to version 1.12.9-1.el8_10 or later.
Which systems are affected by RHSA-2024:3961?
RHSA-2024:3961 affects multiple systems including Red Hat Enterprise Linux for x86_64, ARM 64, IBM z Systems, and Power architectures.
What is the impacted package version in RHSA-2024:3961?
The impacted package version in RHSA-2024:3961 is flatpak prior to 1.12.9-1.el8_10.