flatpak is vulnerable to Link Following
52
Medium Risk
When regenerating the runtime linker cache, Flatpak writes to ~/.var/app/$appid/.ld.so, a path a sandboxed app fully controls. A malicious app can replace that file with a symlink so that the cache regeneration writes its output at an arbitrary location outside the sandbox. The filename and content are fixed, which limits exploitability, but the write still escapes the sandbox. The fix hardens the symlink switch and cache regeneration to use fd-based operations.
You are affected if you are using a version that falls within the vulnerable range.
flatpak is vulnerable to Link Following in versions 0.0.1 - 1.18.0.
Upgrade the flatpak library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant