Bug 28575 - flatpak new security issue fixed upstream in 1.10.2 (CVE-2021-21381)
Summary: flatpak new security issue fixed upstream in 1.10.2 (CVE-2021-21381)
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks: 27126
  Show dependency treegraph
 
Reported: 2021-03-10 18:13 CET by David Walser
Modified: 2021-03-30 23:09 CEST (History)
5 users (show)

See Also:
Source RPM: flatpak-1.10.1-1.mga8.src.rpm
CVE: CVE-2021-21381
Status comment:


Attachments

Description David Walser 2021-03-10 18:13:49 CET
Upstream has issued an advisory today (March 10):
https://github.com/flatpak/flatpak/security/advisories/GHSA-xgh4-387p-hqpp

A CVE has been requested:
https://github.com/flatpak/flatpak/issues/4146#issuecomment-795302663

The issue is fixed upstream in 1.10.2:
https://github.com/flatpak/flatpak/releases/tag/1.10.2

Mageia 7 and Mageia 8 are also affected.
David Walser 2021-03-10 18:14:29 CET

Whiteboard: (none) => MGA8TOO, MGA7TOO
Blocks: (none) => 27126
Status comment: (none) => Fixed upstream in 1.10.2

Morgan Leijström 2021-03-10 18:20:28 CET

CC: (none) => fri

Comment 1 Nicolas Lécureuil 2021-03-10 18:57:10 CET
fixed in cauldron/mga8

src:
   - mageia 8:
              - flatpak-1.10.2-1.mga8

Mageia 7 is in progress

CC: (none) => mageia

Comment 2 David Walser 2021-03-10 21:05:59 CET
You can handle Mageia 7 in the other bug if you'd like.

Whiteboard: MGA8TOO, MGA7TOO => MGA7TOO
Version: Cauldron => 8

Comment 3 Lewis Smith 2021-03-10 21:55:57 CET
Assigning to you Nicolas as you are already doing it!

Source RPM: flatpak-1.10.1-1.mga8.src.rpm => flatpak-1.10.1-1.mga8.src.rpm, flatpak-1.4.1-1.mga7.src.rpm
Assignee: bugsquad => mageia

Nicolas Lécureuil 2021-03-11 08:55:10 CET

Assignee: mageia => qa-bugs

Comment 4 David Walser 2021-03-11 16:10:18 CET
Mageia 7 in Bug 27126.

Whiteboard: MGA7TOO => (none)
Status comment: Fixed upstream in 1.10.2 => (none)
Source RPM: flatpak-1.10.1-1.mga8.src.rpm, flatpak-1.4.1-1.mga7.src.rpm => flatpak-1.10.1-1.mga8.src.rpm

Comment 5 David Walser 2021-03-12 20:24:10 CET
CVE-2021-21381 has been assigned:
https://github.com/flatpak/flatpak/issues/4146#issuecomment-796918073

Advisory:
========================

Updated flatpak packages fix security vulnerability:

A potential attack where a flatpak application could use custom formatted
.desktop files to gain access to files on the host system (CVE-2021-21381).

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21381
https://github.com/flatpak/flatpak/security/advisories/GHSA-xgh4-387p-hqpp
https://github.com/flatpak/flatpak/releases/tag/1.10.2
https://github.com/flatpak/flatpak/issues/4146

Summary: flatpak new security issue fixed upstream in 1.10.2 => flatpak new security issue fixed upstream in 1.10.2 (CVE-2021-21381)

Comment 6 David Walser 2021-03-12 20:26:21 CET
Does gnome-software need to be rebuilt for this one?
Comment 7 Nicolas Lécureuil 2021-03-12 20:34:34 CET
ah yes maybe we need to rebuild it and discover.
Comment 8 David Walser 2021-03-12 20:49:38 CET
discover was already built after this one.
Comment 9 Guillaume Royer 2021-03-13 15:55:28 CET
I have installed 1.10.2-1 Flatpak on MGA8 XFCE Desktop kernel 5.10.20-desktop-2.mga8

Installed with: 

flatpak-1.10.2-1.mga8.x86_64.rpm
lib64flatpak-devel-1.10.2-1.mga8.x86_64.rpm
lib64flatpak-gir1.0-1.10.2-1.mga8.x86_64.rpm
lib64flatpak0-1.10.2-1.mga8.x86_64.rpm

The installation is done correctly without error messages.


Gnome-software is at V3.38.0, I used it to do an upgrade, no problems found

CC: (none) => guillaume.royer

Comment 10 Aurelien Oudelet 2021-03-17 18:03:12 CET
MGA8 x86_64 Plasma

Using Howto on https://github.com/flatpak/flatpak/issues/4146#issuecomment-796918073
Reproduced behaviour, to get file normally inaccessible from flatpak app.
(/etc/passwd) in this case.

Updating.
No longer reproduced.

MGA8-64-OK
Validating.
Advisory committed to SVN.

CC: (none) => ouaurelien, sysadmin-bugs
Keywords: (none) => advisory, validated_update
CVE: (none) => CVE-2021-21381
Whiteboard: (none) => MGA8-64-OK

Comment 11 Mageia Robot 2021-03-18 10:57:38 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2021-0145.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED

Comment 12 David Walser 2021-03-30 23:09:55 CEST
RedHat has issued an advisory for this on March 29:
https://access.redhat.com/errata/RHSA-2021:1002

Note You need to log in before you can comment on or make changes to this bug.