Fedora Account System
Red Hat Associate
Red Hat Customer
GHSA-w69g-9x8j-7p8f (https://github.com/flatpak/flatpak/security/advisories/GHSA-w69g-9x8j-7p8f) Description: When Flatpak launches an application, it performs host-side file operations inside extension content directories to set up bind mounts and symlinks, using path-based APIs that follow symlinks without confinement. Since an extension's files directory is entirely controlled by the extension developer, a malicious extension can place symlinks pointing at arbitrary host paths. Flatpak follows symlinks in the extension content when checking for the .ref lock marker file and when iterating merge_dirs directories; for merge_dirs, the host-side directory listing is reflected into the sandbox as symlinks the application can enumerate, disclosing filenames from arbitrary host directories. Separately, extension metadata fields (directory, subdir_suffix, add_ld_path, merge_dirs) were not validated for path traversal, allowing extension content to be mounted at unintended sandbox locations. Mitigation: Avoid installing Flatpak extensions from untrusted sources; there is no configuration to disable extension processing without removing the extensions. Fixed in 1.18.1 (backports available for 1.16.x). Reported by @swick.