CVE-2021-41133
Severity
7.8HIGH
EPSS
0.1%
top 81.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 8
Latest updateDec 14
Description
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior to 1.10.4 and 1.12.0, Flatpak apps with direct access to AF_UNIX sockets such as those used by Wayland, Pipewire or pipewire-pulse can trick portals and other host-OS services into treating the Flatpak app as though it was an ordinary, non-sandboxed host-OS process. They can do this by manipulating the VFS using recent mount-related syscalls that are not blocked by Flatpak's den…
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 2.0 | Impact: 6.0
Affected Packages3 packages
Also affects: Debian Linux 11.0, Fedora 33, 34
Patches
🔴Vulnerability Details
2📋Vendor Advisories
4Debian▶
CVE-2021-41133: flatpak - Flatpak is a system for building, distributing, and running sandboxed desktop ap...↗2021