Fedora Account System
Red Hat Associate
Red Hat Customer
Description of problem: https://seclists.org/oss-sec/2021/q1/121 Summary: A vulnerability resulting in root privilege escalation was discovered in Firejail's OverlayFS code, Versions affected: Firejail software versions starting with 0.9.30. Long Term Support (LTS) Firejail branch is not affected by this bug. Workaround: Disable overlayfs feature at runtime. In a text editor open /etc/firejail/firejail.config file, and set "overlayfs" entry to "no". Fix: The bug is fixed in Firejail version 0.9.64.4 Additional info: Firejail was updated in Rawhide but not Fedora 33.
Issue is fixed in f34 as well, do you have a reason not updating to f34 ?
My issue was posted multiple times due to bugzilla glitch. I plan on updating to Fedora 34 when it is released, but it is currently not even in beta.
*** Bug 1929623 has been marked as a duplicate of this bug. ***
I do not see this as a priority issue, as it is fixed in f34 and workaround exists. Closing this issue as WONTFIX.
*** Bug 1929620 has been marked as a duplicate of this bug. ***
*** Bug 1929621 has been marked as a duplicate of this bug. ***
*** Bug 1929622 has been marked as a duplicate of this bug. ***
*** Bug 1929624 has been marked as a duplicate of this bug. ***