Skip to content

CVE-2019-10063: Incomplete fix for CVE-2017-5226, sandbox escape via TIOCSTI ioctl

High
smcv published GHSA-5mm6-ffvm-prvg Mar 2, 2023

Package

Flatpak (freedesktop.org)

Affected versions

< 1.3.1

Patched versions

1.3.1, 1.2.4, 1.0.8

Description

(Advisory created in 2023 to clarify the handling of a security issue in much older versions.)

Impact

If Flatpak is run from a terminal emulator containing an interactive shell, a malicious Flatpak app could inject input into the interactive shell by using the TIOCSTI ioctl due to an incomplete solution for CVE-2017-5226.

Patches

a9107fe

Workarounds

Don't run Flatpak apps with a controlling terminal, or don't use Flatpak versions from 2019.

References

#2782

Severity

High

CVE ID

CVE-2019-10063

Weaknesses

No CWEs