Fedora Account System
Red Hat Associate
Red Hat Customer
GHSA-q4gr-vc25-57m5 (https://github.com/flatpak/flatpak/security/advisories/GHSA-q4gr-vc25-57m5) Description: By using the system helper's unprivileged RemoveLocalRef method, an attacker was able to remove the remote ref of the app or runtime. The anti-downgrade check would fail to find the remote ref, and with it the date to check against, allowing an attacker to bypass the check and downgrade apps. Mitigation: Ensure that Flatpak apps installed system-wide are fully updated before running them. Fixed in 1.18.1 (backports available for 1.16.x). Discovered and reported by BreachX Zero Day Labs, using Typhon AI Mil v2. Contributing Researcher: Vivek Parikh.