CVE-2023-28100

Severity
6.5MEDIUM
EPSS
0.7%
top 28.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 16

Description

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. Versions prior to 1.10.8, 1.12.8, 1.14.4, and 1.15.4 contain a vulnerability similar to CVE-2017-5226, but using the `TIOCLINUX` ioctl command instead of `TIOCSTI`. If a Flatpak app is run on a Linux virtual console such as `/dev/tty1`, it can copy text from the virtual console and paste it into the command buffer, from which the command might be run after the Flatpak app has exited. Ordinary gra

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HExploitability: 3.9 | Impact: 6.0

Affected Packages3 packages

CVEListV5flatpak/flatpak< 1.10.8+3
NVDflatpak/flatpak1.12.01.12.8+3
Debianflatpak< 1.10.8-0+deb11u1+3

Patches

🔴Vulnerability Details

2
OSV
CVE-2023-28100: Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux2023-03-16
CVEList
TIOCLINUX can send commands outside sandbox if running on a virtual console2023-03-16

📋Vendor Advisories

2
Red Hat
flatpak: TIOCLINUX can send commands outside sandbox if running on a virtual console2023-03-16
Debian
CVE-2023-28100: flatpak - Flatpak is a system for building, distributing, and running sandboxed desktop ap...2023
CVE-2023-28100 (MEDIUM CVSS 6.5) | Flatpak is a system for building | cvebase.io