CVE-2019-8308
published 2019-02-12CVE-2019-8308: Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side…
PriorityP433high8.2CVSS 3.0
AVLACLPRLUIRSCCHIHAH
EPSS
0.47%
37.8th percentile
Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side executable file.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | flatpak | < flatpak 1.2.3-1 (bookworm) | flatpak 1.2.3-1 (bookworm) |
| flatpak | flatpak | < 1.0.7 | 1.0.7 |
| flatpak | flatpak | >= 0 < 1.2.3-1 | 1.2.3-1 |
| flatpak | flatpak | >= 0 < 1.2.3-1 | 1.2.3-1 |
| flatpak | flatpak | >= 0 < 1.2.3-1 | 1.2.3-1 |
| flatpak | flatpak | >= 0 < 1.2.3-1 | 1.2.3-1 |
| flatpak | flatpak | 1.1.0 – 1.1.3 | — |
| flatpak | flatpak | 1.2.0 – 1.2.3 | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.08.2HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv8.2HIGH
vendor_debian8.2HIGH
vendor_redhat8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-26wh-22xw-qfqx: Flatpak before 1
ghsa_unreviewed·2022-05-13
CVE-2019-8308 [HIGH] CWE-668 GHSA-26wh-22xw-qfqx: Flatpak before 1
Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side executable file.
OSV
CVE-2019-8308: Flatpak before 1
osv·2019-02-12·CVSS 8.2
CVE-2019-8308 [HIGH] CVE-2019-8308: Flatpak before 1
Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side executable file.
Red Hat
flatpak: potential /proc based sandbox escape
vendor_redhat·2019-02-11·CVSS 8.2
CVE-2019-8308 [HIGH] CWE-672 flatpak: potential /proc based sandbox escape
flatpak: potential /proc based sandbox escape
Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side executable file.
A flaw was found in flatpak. In certain special cases, installing flatpak applications and runtimes system-wide may allow an attacker to escape the flatpak sandbox. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Statement: This flaw appears to impact systems in special cases involving installing flatpak applications and runtimes system-wide. Installation of flatpak applications and runtimes locally should not be impacted.
Package: flatpak (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2019-8308: flatpak - Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the app...
vendor_debian·2019·CVSS 8.2
CVE-2019-8308 [HIGH] CVE-2019-8308: flatpak - Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the app...
Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side executable file.
Scope: local
bookworm: resolved (fixed in 1.2.3-1)
bullseye: resolved (fixed in 1.2.3-1)
forky: resolved (fixed in 1.2.3-1)
sid: resolved (fixed in 1.2.3-1)
trixie: resolved (fixed in 1.2.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-8308 flatpak: potential /proc based sandbox escape [fedora-all]
bugzilla·2019-02-11·CVSS 8.2
CVE-2019-8308 [HIGH] CVE-2019-8308 flatpak: potential /proc based sandbox escape [fedora-all]
CVE-2019-8308 flatpak: potential /proc based sandbox escape [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of F
Bugzilla
CVE-2019-8308 flatpak: potential /proc based sandbox escape
bugzilla·2019-02-11·CVSS 8.2
CVE-2019-8308 [HIGH] CVE-2019-8308 flatpak: potential /proc based sandbox escape
CVE-2019-8308 flatpak: potential /proc based sandbox escape
A flaw was discovered that may allow an attacker to escape from the flatpak sandbox via /proc/self/exe.
Upstream Commit:
https://github.com/flatpak/flatpak/commit/cd2142888fc4c199723a0dfca1f15ea8788a5483
Discussion:
Created flatpak tracking bugs for this issue:
Affects: fedora-all [bug 1675432]
---
My current understanding is that the only portion of flatpak that should run as root is the system-helper. The system-helper functionality may call into apply_extra_data(), which eventually calls flatpak_run_setup_base_argv. The patch adds a new flag, FLATPAK_RUN_FLAG_NO_PROC, to ensure that proc isn't reachable during this operation.
From the devs (paraphrasing) -- this (running as root) should only happen during installation t
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00088.htmlhttps://access.redhat.com/errata/RHSA-2019:0375https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=922059https://github.com/flatpak/flatpak/releases/tag/1.0.7https://github.com/flatpak/flatpak/releases/tag/1.2.3http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00088.htmlhttps://access.redhat.com/errata/RHSA-2019:0375https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=922059https://github.com/flatpak/flatpak/releases/tag/1.0.7https://github.com/flatpak/flatpak/releases/tag/1.2.3
2019-02-12
Published