started · updated
Flatpak releases security updates to address sandbox escape vulnerabilities
Flatpak has released new updates, including version 1.19 and the stable version 1.18.1, to address several critical security vulnerabilities. These updates focus on fixing flaws in the application sandboxing and distribution technology.
A primary concern addressed is a sandbox escape vulnerability where a manipulated application could use symbolic links to gain unauthorized read and write access to the host file system. Additionally, the updates resolve a local privilege escalation flaw that could allow access to root privileges via revokefs symlink traversal.
Other technical fixes include addressing buffer overflows on 32-bit systems, path traversal vulnerabilities during OCI unpacking, and issues related to application downgrades. Version 1.19 also introduces functional improvements such as system downgrades via a system helper and enhanced Bash auto-completion logic.