CVE-2021-41133

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior to 1.10.4 and 1.12.0, Flatpak apps with direct access to AF_UNIX sockets such as those used by Wayland, Pipewire or pipewire-pulse can trick portals and other host-OS services into treating the Flatpak app as though it was an ordinary, non-sandboxed host-OS process. They can do this by manipulating the VFS using recent mount-related syscalls that are not blocked by Flatpak's denylist seccomp filter, in order to substitute a crafted `/.flatpak-info` or make that file disappear entirely. Flatpak apps that act as clients for AF_UNIX sockets such as those used by Wayland, Pipewire or pipewire-pulse can escalate the privileges that the corresponding services will believe the Flatpak app has. Note that protocols that operate entirely over the D-Bus session bus (user bus), system bus or accessibility bus are not affected by this. This is due to the use of a proxy process `xdg-dbus-proxy`, whose VFS cannot be manipulated by the Flatpak app, when interacting with these buses. Patches exist for versions 1.10.4 and 1.12.0, and as of time of publication, a patch for version 1.8.2 is being planned. There are no workarounds aside from upgrading to a patched version.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 19%
Affected Products (NVD)
VendorProductVersion
flatpakflatpak
𝑥
< 1.8.2
flatpakflatpak
1.10.0 ≤
𝑥
< 1.10.4
flatpakflatpak
1.11.1 ≤
𝑥
< 1.12.1
debiandebian_linux
11.0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
flatpakflatpak
1.10.0 ≤
𝑥
≤ 1.10.4
ADP
flatpakflatpak
1.11.0 ≤
𝑥
< 1.12.0
ADP
flatpakflatpak
1.8.0 ≤
𝑥
< 1.8.2
ADP
Debian logo
Debian Releases
Debian Product
Codename
flatpak
bookworm
1.14.10-1~deb12u1
fixed
bookworm (security)
1.14.10-1~deb12u1
fixed
bullseye
1.10.8-0+deb11u2
fixed
bullseye (security)
1.10.8-0+deb11u2
fixed
buster
ignored
sid
1.14.10-1
fixed
stretch
ignored
trixie
1.14.10-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
flatpak
bionic
Fixed 1.0.9-0ubuntu0.4
released
focal
Fixed 1.6.5-0ubuntu0.4
released
hirsute
Fixed 1.10.2-1ubuntu1.1
released
impish
Fixed 1.10.2-3ubuntu0.1
released
jammy
not-affected
trusty
dne
xenial
ignored
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
flatpak
suse enterprise desktop 15 SP2
1.10.5-4.9.1
fixed
suse enterprise desktop 15 SP3
1.10.5-4.9.1
fixed
suse enterprise desktop 15 SP4
1.12.5-150400.1.11
fixed
suse enterprise desktop 15 SP5
1.14.4-150500.1.3
fixed
suse enterprise desktop 15 SP6
1.14.6-150600.1.2
fixed
suse enterprise desktop 15 SP7
1.16.0-150600.3.6.1
fixed
suse enterprise sap 15 SP2
1.10.5-4.9.1
fixed
suse enterprise sap 15 SP3
1.10.5-4.9.1
fixed
suse enterprise sap 15 SP4
1.12.5-150400.1.11
fixed
suse enterprise sap 15 SP5
1.14.4-150500.1.3
fixed
suse enterprise sap 15 SP6
1.14.6-150600.1.2
fixed
suse enterprise sap 15 SP7
1.16.0-150600.3.6.1
fixed
suse enterprise server 15
0.10.4-150000.4.13.1
fixed
suse enterprise server 15 SP1
1.2.3-150100.4.8.1
fixed
suse enterprise server 15 SP2
1.10.5-4.9.1
fixed
suse enterprise server 15 SP3
1.10.5-4.9.1
fixed
suse enterprise server 15 SP4
1.12.5-150400.1.11
fixed
suse enterprise server 15 SP5
1.14.4-150500.1.3
fixed
suse enterprise server 15 SP6
1.14.6-150600.1.2
fixed
suse enterprise server 15 SP7
1.16.0-150600.3.6.1
fixed
flatpak-devel
suse enterprise desktop 15 SP2
1.10.5-4.9.1
fixed
suse enterprise desktop 15 SP3
1.10.5-4.9.1
fixed
suse enterprise desktop 15 SP4
1.12.5-150400.1.11
fixed
suse enterprise desktop 15 SP5
1.14.4-150500.1.3
fixed
suse enterprise desktop 15 SP6
1.14.6-150600.1.2
fixed
suse enterprise desktop 15 SP7
1.16.0-150600.3.6.1
fixed
suse enterprise sap 15 SP2
1.10.5-4.9.1
fixed
suse enterprise sap 15 SP3
1.10.5-4.9.1
fixed
suse enterprise sap 15 SP4
1.12.5-150400.1.11
fixed
suse enterprise sap 15 SP5
1.14.4-150500.1.3
fixed
suse enterprise sap 15 SP6
1.14.6-150600.1.2
fixed
suse enterprise sap 15 SP7
1.16.0-150600.3.6.1
fixed
suse enterprise server 15
0.10.4-150000.4.13.1
fixed
suse enterprise server 15 SP1
1.2.3-150100.4.8.1
fixed
suse enterprise server 15 SP2
1.10.5-4.9.1
fixed
suse enterprise server 15 SP3
1.10.5-4.9.1
fixed
suse enterprise server 15 SP4
1.12.5-150400.1.11
fixed
suse enterprise server 15 SP5
1.14.4-150500.1.3
fixed
suse enterprise server 15 SP6
1.14.6-150600.1.2
fixed
suse enterprise server 15 SP7
1.16.0-150600.3.6.1
fixed
flatpak-remote-flathub
suse enterprise desktop 15 SP5
1.14.4-150500.1.3
fixed
suse enterprise desktop 15 SP6
1.14.6-150600.1.2
fixed
suse enterprise desktop 15 SP7
1.16.0-150600.3.6.1
fixed
suse enterprise sap 15 SP5
1.14.4-150500.1.3
fixed
suse enterprise sap 15 SP6
1.14.6-150600.1.2
fixed
suse enterprise sap 15 SP7
1.16.0-150600.3.6.1
fixed
suse enterprise server 15 SP5
1.14.4-150500.1.3
fixed
suse enterprise server 15 SP6
1.14.6-150600.1.2
fixed
suse enterprise server 15 SP7
1.16.0-150600.3.6.1
fixed
flatpak-zsh-completion
suse enterprise desktop 15 SP2
1.10.5-4.9.1
fixed
suse enterprise desktop 15 SP3
1.10.5-4.9.1
fixed
suse enterprise desktop 15 SP4
1.12.5-150400.1.11
fixed
suse enterprise desktop 15 SP5
1.14.4-150500.1.3
fixed
suse enterprise desktop 15 SP6
1.14.6-150600.1.2
fixed
suse enterprise desktop 15 SP7
1.16.0-150600.3.6.1
fixed
suse enterprise sap 15 SP2
1.10.5-4.9.1
fixed
suse enterprise sap 15 SP3
1.10.5-4.9.1
fixed
suse enterprise sap 15 SP4
1.12.5-150400.1.11
fixed
suse enterprise sap 15 SP5
1.14.4-150500.1.3
fixed
suse enterprise sap 15 SP6
1.14.6-150600.1.2
fixed
suse enterprise sap 15 SP7
1.16.0-150600.3.6.1
fixed
suse enterprise server 15 SP1
1.2.3-150100.4.8.1
fixed
suse enterprise server 15 SP2
1.10.5-4.9.1
fixed
suse enterprise server 15 SP3
1.10.5-4.9.1
fixed
suse enterprise server 15 SP4
1.12.5-150400.1.11
fixed
suse enterprise server 15 SP5
1.14.4-150500.1.3
fixed
suse enterprise server 15 SP6
1.14.6-150600.1.2
fixed
suse enterprise server 15 SP7
1.16.0-150600.3.6.1
fixed
libflatpak0
suse enterprise desktop 15 SP2
1.10.5-4.9.1
fixed
suse enterprise desktop 15 SP3
1.10.5-4.9.1
fixed
suse enterprise desktop 15 SP4
1.12.5-150400.1.11
fixed
suse enterprise desktop 15 SP5
1.14.4-150500.1.3
fixed
suse enterprise desktop 15 SP6
1.14.6-150600.1.2
fixed
suse enterprise desktop 15 SP7
1.16.0-150600.3.6.1
fixed
suse enterprise sap 15 SP2
1.10.5-4.9.1
fixed
suse enterprise sap 15 SP3
1.10.5-4.9.1
fixed
suse enterprise sap 15 SP4
1.12.5-150400.1.11
fixed
suse enterprise sap 15 SP5
1.14.4-150500.1.3
fixed
suse enterprise sap 15 SP6
1.14.6-150600.1.2
fixed
suse enterprise sap 15 SP7
1.16.0-150600.3.6.1
fixed
suse enterprise server 15
0.10.4-150000.4.13.1
fixed
suse enterprise server 15 SP1
1.2.3-150100.4.8.1
fixed
suse enterprise server 15 SP2
1.10.5-4.9.1
fixed
suse enterprise server 15 SP3
1.10.5-4.9.1
fixed
suse enterprise server 15 SP4
1.12.5-150400.1.11
fixed
suse enterprise server 15 SP5
1.14.4-150500.1.3
fixed
suse enterprise server 15 SP6
1.14.6-150600.1.2
fixed
suse enterprise server 15 SP7
1.16.0-150600.3.6.1
fixed
system-user-flatpak
suse enterprise desktop 15 SP2
1.10.5-4.9.1
fixed
suse enterprise desktop 15 SP3
1.10.5-4.9.1
fixed
suse enterprise desktop 15 SP4
1.12.5-150400.1.11
fixed
suse enterprise desktop 15 SP5
1.14.4-150500.1.3
fixed
suse enterprise desktop 15 SP6
1.14.6-150600.1.2
fixed
suse enterprise desktop 15 SP7
1.16.0-150600.3.6.1
fixed
suse enterprise sap 15 SP2
1.10.5-4.9.1
fixed
suse enterprise sap 15 SP3
1.10.5-4.9.1
fixed
suse enterprise sap 15 SP4
1.12.5-150400.1.11
fixed
suse enterprise sap 15 SP5
1.14.4-150500.1.3
fixed
suse enterprise sap 15 SP6
1.14.6-150600.1.2
fixed
suse enterprise sap 15 SP7
1.16.0-150600.3.6.1
fixed
suse enterprise server 15 SP2
1.10.5-4.9.1
fixed
suse enterprise server 15 SP3
1.10.5-4.9.1
fixed
suse enterprise server 15 SP4
1.12.5-150400.1.11
fixed
suse enterprise server 15 SP5
1.14.4-150500.1.3
fixed
suse enterprise server 15 SP6
1.14.6-150600.1.2
fixed
suse enterprise server 15 SP7
1.16.0-150600.3.6.1
fixed
typelib-1_0-Flatpak-1_0
suse enterprise desktop 15 SP2
1.10.5-4.9.1
fixed
suse enterprise desktop 15 SP3
1.10.5-4.9.1
fixed
suse enterprise desktop 15 SP4
1.12.5-150400.1.11
fixed
suse enterprise desktop 15 SP5
1.14.4-150500.1.3
fixed
suse enterprise desktop 15 SP6
1.14.6-150600.1.2
fixed
suse enterprise desktop 15 SP7
1.16.0-150600.3.6.1
fixed
suse enterprise sap 15 SP2
1.10.5-4.9.1
fixed
suse enterprise sap 15 SP3
1.10.5-4.9.1
fixed
suse enterprise sap 15 SP4
1.12.5-150400.1.11
fixed
suse enterprise sap 15 SP5
1.14.4-150500.1.3
fixed
suse enterprise sap 15 SP6
1.14.6-150600.1.2
fixed
suse enterprise sap 15 SP7
1.16.0-150600.3.6.1
fixed
suse enterprise server 15
0.10.4-150000.4.13.1
fixed
suse enterprise server 15 SP1
1.2.3-150100.4.8.1
fixed
suse enterprise server 15 SP2
1.10.5-4.9.1
fixed
suse enterprise server 15 SP3
1.10.5-4.9.1
fixed
suse enterprise server 15 SP4
1.12.5-150400.1.11
fixed
suse enterprise server 15 SP5
1.14.4-150500.1.3
fixed
suse enterprise server 15 SP6
1.14.6-150600.1.2
fixed
suse enterprise server 15 SP7
1.16.0-150600.3.6.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
flatpak
RHEL 7
0:1.0.9-12.el7_9
fixed
RHEL 8
0:1.8.5-4.el8_4
fixed
RHEL 8.1 E4S
0:1.0.9-5.el8_1
fixed
RHEL 8.1 EUS
0:1.0.9-5.el8_1
fixed
RHEL 8.2 AUS
0:1.6.2-6.el8_2
fixed
RHEL 8.2 E4S
0:1.6.2-6.el8_2
fixed
RHEL 8.2 EUS
0:1.6.2-6.el8_2
fixed
RHEL 8.2 TUS
0:1.6.2-6.el8_2
fixed
RHEL 8.4 AUS
0:1.8.5-4.el8_4
fixed
RHEL 8.4 E4S
0:1.8.5-4.el8_4
fixed
RHEL 8.4 EUS
0:1.8.5-4.el8_4
fixed
RHEL 8.4 TUS
0:1.8.5-4.el8_4
fixed
flatpak-builder
RHEL 7
0:1.0.0-12.el7_9
fixed
flatpak-devel
RHEL 7
0:1.0.9-12.el7_9
fixed
flatpak-libs
RHEL 7
0:1.0.9-12.el7_9
fixed
RHEL 8
0:1.8.5-4.el8_4
fixed
RHEL 8.1 E4S
0:1.0.9-5.el8_1
fixed
RHEL 8.1 EUS
0:1.0.9-5.el8_1
fixed
RHEL 8.2 AUS
0:1.6.2-6.el8_2
fixed
RHEL 8.2 E4S
0:1.6.2-6.el8_2
fixed
RHEL 8.2 EUS
0:1.6.2-6.el8_2
fixed
RHEL 8.2 TUS
0:1.6.2-6.el8_2
fixed
RHEL 8.4 AUS
0:1.8.5-4.el8_4
fixed
RHEL 8.4 E4S
0:1.8.5-4.el8_4
fixed
RHEL 8.4 EUS
0:1.8.5-4.el8_4
fixed
RHEL 8.4 TUS
0:1.8.5-4.el8_4
fixed
flatpak-selinux
RHEL 8
0:1.8.5-4.el8_4
fixed
RHEL 8.2 AUS
0:1.6.2-6.el8_2
fixed
RHEL 8.2 E4S
0:1.6.2-6.el8_2
fixed
RHEL 8.2 EUS
0:1.6.2-6.el8_2
fixed
RHEL 8.2 TUS
0:1.6.2-6.el8_2
fixed
RHEL 8.4 AUS
0:1.8.5-4.el8_4
fixed
RHEL 8.4 E4S
0:1.8.5-4.el8_4
fixed
RHEL 8.4 EUS
0:1.8.5-4.el8_4
fixed
RHEL 8.4 TUS
0:1.8.5-4.el8_4
fixed
flatpak-session-helper
RHEL 8
0:1.8.5-4.el8_4
fixed
RHEL 8.2 AUS
0:1.6.2-6.el8_2
fixed
RHEL 8.2 E4S
0:1.6.2-6.el8_2
fixed
RHEL 8.2 EUS
0:1.6.2-6.el8_2
fixed
RHEL 8.2 TUS
0:1.6.2-6.el8_2
fixed
RHEL 8.4 AUS
0:1.8.5-4.el8_4
fixed
RHEL 8.4 E4S
0:1.8.5-4.el8_4
fixed
RHEL 8.4 EUS
0:1.8.5-4.el8_4
fixed
RHEL 8.4 TUS
0:1.8.5-4.el8_4
fixed
References