USN-7046-1

Source
https://ubuntu.com/security/notices/USN-7046-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7046-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/USN-7046-1
Related
Published
2024-09-30T18:14:43.852412Z
Modified
2024-09-30T18:14:43.852412Z
Summary
bubblewrap, flatpak vulnerability
Details

It was discovered that Flatpak incorrectly handled certain persisted directories. An attacker could possibly use this issue to read and write files in locations it would not normally have access to. A patch was also needed to Bubblewrap in order to avoid race conditions caused by this fix.

References

Affected packages

Ubuntu:20.04:LTS / bubblewrap

Package

Name
bubblewrap
Purl
pkg:deb/ubuntu/bubblewrap?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.4.0-1ubuntu4.1

Affected versions

0.*

0.3.3-2
0.4.0-1
0.4.0-1ubuntu1
0.4.0-1ubuntu2
0.4.0-1ubuntu3
0.4.0-1ubuntu4

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "0.4.0-1ubuntu4.1",
            "binary_name": "bubblewrap"
        },
        {
            "binary_version": "0.4.0-1ubuntu4.1",
            "binary_name": "bubblewrap-dbgsym"
        }
    ]
}

Ubuntu:20.04:LTS / flatpak

Package

Name
flatpak
Purl
pkg:deb/ubuntu/flatpak?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.5-0ubuntu0.5

Affected versions

1.*

1.4.3-1
1.6.0-1
1.6.1-1
1.6.2-1
1.6.3-1
1.6.5-0ubuntu0.1
1.6.5-0ubuntu0.2
1.6.5-0ubuntu0.3
1.6.5-0ubuntu0.4

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "1.6.5-0ubuntu0.5",
            "binary_name": "flatpak"
        },
        {
            "binary_version": "1.6.5-0ubuntu0.5",
            "binary_name": "flatpak-dbgsym"
        },
        {
            "binary_version": "1.6.5-0ubuntu0.5",
            "binary_name": "flatpak-tests"
        },
        {
            "binary_version": "1.6.5-0ubuntu0.5",
            "binary_name": "flatpak-tests-dbgsym"
        },
        {
            "binary_version": "1.6.5-0ubuntu0.5",
            "binary_name": "gir1.2-flatpak-1.0"
        },
        {
            "binary_version": "1.6.5-0ubuntu0.5",
            "binary_name": "libflatpak-dev"
        },
        {
            "binary_version": "1.6.5-0ubuntu0.5",
            "binary_name": "libflatpak-doc"
        },
        {
            "binary_version": "1.6.5-0ubuntu0.5",
            "binary_name": "libflatpak0"
        },
        {
            "binary_version": "1.6.5-0ubuntu0.5",
            "binary_name": "libflatpak0-dbgsym"
        }
    ]
}

Ubuntu:22.04:LTS / bubblewrap

Package

Name
bubblewrap
Purl
pkg:deb/ubuntu/bubblewrap?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.1-1ubuntu0.1

Affected versions

0.*

0.4.1-3build1
0.5.0-1
0.6.0-1
0.6.1-1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "0.6.1-1ubuntu0.1",
            "binary_name": "bubblewrap"
        },
        {
            "binary_version": "0.6.1-1ubuntu0.1",
            "binary_name": "bubblewrap-dbgsym"
        }
    ]
}

Ubuntu:22.04:LTS / flatpak

Package

Name
flatpak
Purl
pkg:deb/ubuntu/flatpak?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.12.7-1ubuntu0.1

Affected versions

1.*

1.10.2-3
1.12.2-1
1.12.2-2
1.12.3-1
1.12.4-1
1.12.5-1
1.12.6-1
1.12.7-1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "1.12.7-1ubuntu0.1",
            "binary_name": "flatpak"
        },
        {
            "binary_version": "1.12.7-1ubuntu0.1",
            "binary_name": "flatpak-dbgsym"
        },
        {
            "binary_version": "1.12.7-1ubuntu0.1",
            "binary_name": "flatpak-tests"
        },
        {
            "binary_version": "1.12.7-1ubuntu0.1",
            "binary_name": "flatpak-tests-dbgsym"
        },
        {
            "binary_version": "1.12.7-1ubuntu0.1",
            "binary_name": "gir1.2-flatpak-1.0"
        },
        {
            "binary_version": "1.12.7-1ubuntu0.1",
            "binary_name": "libflatpak-dev"
        },
        {
            "binary_version": "1.12.7-1ubuntu0.1",
            "binary_name": "libflatpak-doc"
        },
        {
            "binary_version": "1.12.7-1ubuntu0.1",
            "binary_name": "libflatpak0"
        },
        {
            "binary_version": "1.12.7-1ubuntu0.1",
            "binary_name": "libflatpak0-dbgsym"
        }
    ]
}

Ubuntu:24.04:LTS / bubblewrap

Package

Name
bubblewrap
Purl
pkg:deb/ubuntu/bubblewrap?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.0-1ubuntu0.1

Affected versions

0.*

0.8.0-2
0.9.0-1build1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "0.9.0-1ubuntu0.1",
            "binary_name": "bubblewrap"
        },
        {
            "binary_version": "0.9.0-1ubuntu0.1",
            "binary_name": "bubblewrap-dbgsym"
        }
    ]
}

Ubuntu:24.04:LTS / flatpak

Package

Name
flatpak
Purl
pkg:deb/ubuntu/flatpak?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.14.6-1ubuntu0.1

Affected versions

1.*

1.14.4-2
1.14.5-1
1.14.5-1build1
1.14.5-1build4
1.14.5-1build5
1.14.5-1build6
1.14.6-1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "1.14.6-1ubuntu0.1",
            "binary_name": "flatpak"
        },
        {
            "binary_version": "1.14.6-1ubuntu0.1",
            "binary_name": "flatpak-dbgsym"
        },
        {
            "binary_version": "1.14.6-1ubuntu0.1",
            "binary_name": "flatpak-tests"
        },
        {
            "binary_version": "1.14.6-1ubuntu0.1",
            "binary_name": "flatpak-tests-dbgsym"
        },
        {
            "binary_version": "1.14.6-1ubuntu0.1",
            "binary_name": "gir1.2-flatpak-1.0"
        },
        {
            "binary_version": "1.14.6-1ubuntu0.1",
            "binary_name": "libflatpak-dev"
        },
        {
            "binary_version": "1.14.6-1ubuntu0.1",
            "binary_name": "libflatpak-doc"
        },
        {
            "binary_version": "1.14.6-1ubuntu0.1",
            "binary_name": "libflatpak0"
        },
        {
            "binary_version": "1.14.6-1ubuntu0.1",
            "binary_name": "libflatpak0-dbgsym"
        }
    ]
}