USN-7046-1: Flatpak and Bubblewrap vulnerability
It was discovered that Flatpak incorrectly handled certain persisted directories. An attacker could possibly use this issue to read and write files in locations it would not normally have access to. A patch was also needed to Bubblewrap in order to avoid race conditions caused by this fix.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7046-1?
The severity of USN-7046-1 is potentially high due to the risk of unauthorized file access by an attacker.
How do I fix USN-7046-1?
To fix USN-7046-1, update to the recommended package versions: bubblewrap 0.9.0-1ubuntu0.1, flatpak 1.14.6-1ubuntu0.1, or libflatpak0 1.14.6-1ubuntu0.1 for Ubuntu 24.04.
What versions of Ubuntu are affected by USN-7046-1?
USN-7046-1 affects Ubuntu versions 20.04, 22.04, and 24.04.
What are the main components involved in USN-7046-1?
The main components involved in USN-7046-1 are bubblewrap, flatpak, and libflatpak0.
Can USN-7046-1 lead to data breaches?
Yes, USN-7046-1 may allow attackers to read and write files in unauthorized locations, potentially leading to data breaches.