RHSA-2024:6422: Important: bubblewrap and flatpak security update
Bubblewrap (/usr/bin/bwrap) is a core execution engine for unprivileged containers that works as a setuid binary on kernels without user namespaces.Security Fix(es): flatpak: Access to files outside sandbox for apps using persistent= (--persist) (CVE-2024-42472) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Other sources
Important: bubblewrap and flatpak security update
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:6422?
The severity of RHSA-2024:6422 is classified as important.
How do I fix RHSA-2024:6422?
To fix RHSA-2024:6422, you should update the affected packages to the specified remedied versions, namely bubblewrap to 0.4.0-2.el8_10 and flatpak to 1.12.9-3.el8_10.
Which packages are affected by RHSA-2024:6422?
The affected packages in RHSA-2024:6422 include bubblewrap and flatpak across various Red Hat products.
What is CVE-2024-42472 related to RHSA-2024:6422?
CVE-2024-42472 is a vulnerability that allows access to files outside the sandbox for applications using persistent storage in flatpak.
On which systems does RHSA-2024:6422 affect Red Hat products?
RHSA-2024:6422 affects Red Hat Enterprise Linux and CodeReady Linux Builder for various architectures including x86_64, ARM, Power, and IBM z Systems.