First published: Tue Jun 18 2024(Updated: )
Flatpak is a system for building, distributing, and running sandboxed desktop<br>applications on Linux.<br>Security Fix(es):<br><li> flatpak: sandbox escape via RequestBackground portal (CVE-2024-32462)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer the CVE page(s)<br>listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/flatpak | <1.0.9-13.el7_9 | 1.0.9-13.el7_9 |
redhat/flatpak | <1.0.9-13.el7_9 | 1.0.9-13.el7_9 |
redhat/flatpak-builder | <1.0.0-13.el7_9 | 1.0.0-13.el7_9 |
redhat/flatpak-debuginfo | <1.0.9-13.el7_9 | 1.0.9-13.el7_9 |
redhat/flatpak-devel | <1.0.9-13.el7_9 | 1.0.9-13.el7_9 |
redhat/flatpak-libs | <1.0.9-13.el7_9 | 1.0.9-13.el7_9 |
redhat/flatpak-builder | <1.0.0-13.el7_9 | 1.0.0-13.el7_9 |
redhat/flatpak-debuginfo | <1.0.9-13.el7_9 | 1.0.9-13.el7_9 |
redhat/flatpak-devel | <1.0.9-13.el7_9 | 1.0.9-13.el7_9 |
redhat/flatpak-libs | <1.0.9-13.el7_9 | 1.0.9-13.el7_9 |
redhat/flatpak | <1.0.9-13.el7_9 | 1.0.9-13.el7_9 |
redhat/flatpak-builder | <1.0.0-13.el7_9 | 1.0.0-13.el7_9 |
redhat/flatpak-debuginfo | <1.0.9-13.el7_9 | 1.0.9-13.el7_9 |
redhat/flatpak-devel | <1.0.9-13.el7_9 | 1.0.9-13.el7_9 |
redhat/flatpak-libs | <1.0.9-13.el7_9 | 1.0.9-13.el7_9 |
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) | ||
Red Hat Enterprise Linux | ||
Red Hat Enterprise Linux Server for IBM z Systems | ||
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) | ||
Red Hat Enterprise Linux Workstation Supplementary | ||
Red Hat Enterprise Linux for Power, little endian - Extended Update Support | ||
Red Hat Enterprise Linux for Power, big endian | ||
Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian | ||
Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian | ||
Red Hat Enterprise Linux for Scientific Computing | ||
Red Hat Enterprise Linux 8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2024:3980 is classified as important.
To fix RHSA-2024:3980, update the flatpak package to version 1.0.9-13.el7_9 or later.
RHSA-2024:3980 addresses a sandbox escape vulnerability via the RequestBackground portal (CVE-2024-32462).
RHSA-2024:3980 affects various versions of Red Hat Enterprise Linux, including server and workstation editions.
After applying the fix for RHSA-2024:3980, continue to monitor for any unusual behavior in applications running under Flatpak.