RHSA-2024:3980: Important: flatpak security update
Flatpak is a system for building, distributing, and running sandboxed desktopapplications on Linux.Security Fix(es): flatpak: sandbox escape via RequestBackground portal (CVE-2024-32462) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer the CVE page(s)listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:3980?
The severity of RHSA-2024:3980 is classified as important.
How do I fix RHSA-2024:3980?
To fix RHSA-2024:3980, update the flatpak package to version 1.0.9-13.el7_9 or later.
What vulnerability is addressed in RHSA-2024:3980?
RHSA-2024:3980 addresses a sandbox escape vulnerability via the RequestBackground portal (CVE-2024-32462).
Which systems are affected by RHSA-2024:3980?
RHSA-2024:3980 affects various versions of Red Hat Enterprise Linux, including server and workstation editions.
What should I monitor after applying the fix for RHSA-2024:3980?
After applying the fix for RHSA-2024:3980, continue to monitor for any unusual behavior in applications running under Flatpak.