Bug 1929621

Summary: Please update firejail in F33 to 0.9.64.4 to fix root privilege escalation in OverlayFS code (CVE-2021-26910)
Product: [Fedora] Fedora Reporter: P D <pizzadudedotca>
Component: firejailAssignee: Ondrej Dubaj <odubaj>
Status: CLOSED DUPLICATE QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: high Docs Contact:
Priority: unspecified    
Version: 33CC: odubaj
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-02-24 07:33:32 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description P D 2021-02-17 10:25:20 UTC
Description of problem:

https://seclists.org/oss-sec/2021/q1/121

Summary: A vulnerability resulting in root privilege escalation was discovered in Firejail's OverlayFS code,

Versions affected: Firejail software versions starting with 0.9.30.
Long Term Support (LTS) Firejail branch is not affected by this bug.

Workaround: Disable overlayfs feature at runtime. In a text editor open /etc/firejail/firejail.config file,
and set "overlayfs" entry to "no".

Fix: The bug is fixed in Firejail version 0.9.64.4


Additional info:

Firejail was updated in Rawhide but not Fedora 33.

Comment 1 Ondrej Dubaj 2021-02-24 07:33:32 UTC

*** This bug has been marked as a duplicate of bug 1929625 ***