Bug 33510 - flatpak new security issue CVE-2024-42472
Summary: flatpak new security issue CVE-2024-42472
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2024-09-02 12:32 CEST by Nicolas Salguero
Modified: 2025-11-19 03:17 CET (History)
6 users (show)

See Also:
Source RPM: flatpak-1.14.6-1.mga9.src.rpm
CVE: CVE-2024-42472
Status comment:


Attachments

Description Nicolas Salguero 2024-09-02 12:32:20 CEST
CVE-2024-42472 was announced here:
https://openwall.com/lists/oss-security/2024/08/14/6

Mageia 9 is also affected.

The problem is fixed in versions 1.15.10 (Cauldron) and 1.14.10 (Mageia 9).
Nicolas Salguero 2024-09-02 12:33:23 CEST

CVE: (none) => CVE-2024-42472
Whiteboard: (none) => MGA9TOO
Source RPM: (none) => flatpak-1.15.8-1.mga10.src.rpm, flatpak-1.14.6-1.mga9.src.rpm

Comment 1 Marja Van Waes 2024-09-04 08:22:54 CEST
Assigning to the registered maintainer, CC'ing the de facto maintainer

CC: (none) => geiger.david68210, marja11
Assignee: bugsquad => mageia

Nicolas Salguero 2025-11-13 14:51:46 CET

Source RPM: flatpak-1.15.8-1.mga10.src.rpm, flatpak-1.14.6-1.mga9.src.rpm => flatpak-1.15.8-4.mga10.src.rpm, flatpak-1.14.6-1.mga9.src.rpm

Comment 2 katnatek 2025-11-13 22:32:20 CET
Is neoclust still in mageia? 
I not hear anything of him these days

CC: (none) => pkg-bugs

Nicolas Salguero 2025-11-14 16:15:52 CET

Whiteboard: MGA9TOO => (none)
Version: Cauldron => 9
Source RPM: flatpak-1.15.8-4.mga10.src.rpm, flatpak-1.14.6-1.mga9.src.rpm => flatpak-1.14.6-1.mga9.src.rpm

Comment 3 Nicolas Salguero 2025-11-17 12:04:09 CET
Suggested advisory:
========================

The updated packages fix a security vulnerability:

Flatpak may allow access to files outside sandbox for certain apps. (CVE-2024-42472)

References:
https://openwall.com/lists/oss-security/2024/08/14/6
========================

Updated packages in core/updates_testing:
========================
bubblewrap-0.7.0-1.1.mga9

flatpak-1.14.10-1.mga9
flatpak-tests-1.14.10-1.mga9
lib(64)flatpak-devel-1.14.10-1.mga9
lib(64)flatpak-gir1.0-1.14.10-1.mga9
lib(64)flatpak0-1.14.10-1.mga9

from SRPMS:
bubblewrap-0.7.0-1.1.mga9.src.rpm
flatpak-1.14.10-1.mga9.src.rpm

Status: NEW => ASSIGNED
Assignee: mageia => qa-bugs

Comment 4 Morgan Leijström 2025-11-17 16:51:16 CET
mga9-64

Strange: flatpak Firefox works in our current version, but not this update, see below

Updated all packages in testing repo, still running on kernel-desktop-6.6.105-1.
System details in https://bugs.mageia.org/show_bug.cgi?id=34408#c25

For this updated to:
- flatpak-1.14.10-1.mga9.x86_64
- lib64flatpak-gir1.0-1.14.10-1.mga9.x86_64
- lib64flatpak0-1.14.10-1.mga9.x86_64

Tests OK:
$ flatpak update
-> Updated some flatpackages OK

__Used installed flatpak programs:

§ KiCad: Launches OK (have not learned to use it yet) 

§ Chromium: Surfing OK

§ Firefox: Do not launch at all:
[morgan@svarten ~]$ flatpak run org.mozilla.firefox
(flatpak run:170595): GLib-GIO-WARNING **: 16:35:39.592: /usr/share/applications/kde-mimeapps.list contains a [Added Associations] group, but it is not permitted here.  Only the non-desktop-specific mimeapps.list file may add or remove associations.
bwrap: Unknown option --bind-fd

After reverting the update using
[morgan@svarten ~]$ sudo urpmi --downgrade flatpak-1.14.6-1.mga9
-> Firefox works.

[morgan@svarten ~]$ flatpak list | grep firef
Firefox org.mozilla.firefox     145.0   stable  flathub user

CC: (none) => fri
Keywords: (none) => feedback

Comment 5 Nicolas Salguero 2025-11-17 17:15:56 CET
You need to update bubblewrap too.

Keywords: feedback => (none)

katnatek 2025-11-17 18:22:13 CET

Keywords: (none) => advisory

Comment 6 Morgan Leijström 2025-11-17 19:10:07 CET
Ah thanks, I jumped too far into the rpm list!
Firefox OK and also tested a few more apps.
BTW now running kernel linus 6.6.116

mga9-64 OK here
Comment 7 Thomas Andrews 2025-11-18 03:52:27 CET
MGA9-64 Plasma, i5-7500,Nvidia Quadro K620 graphics (nvidia-current). No installation issues.

Ran Discover, checked for updates, found two that were relevant - Space Cadet Pinball and the Surfshark VPN app. I updated those, seemingly without issues. 

The Surfshark app worked as it should, but the pinball simulation has a regression in that it now doesn't work in maximized or full screen mode. Only part of the screen is shown. And if you try to expand the game window from the non-maximized state, the window expands but the game doesn't. Game play is normal in the smaller window.

I do not believe this regression has anything to do with the flatpak update, but with rather the game I updated with it, so I'm giving this an OK, and validating.

CC: (none) => andrewsfarm, sysadmin-bugs
Whiteboard: (none) => MGA9-64-OK
Keywords: (none) => validated_update

Comment 8 Mageia Robot 2025-11-19 03:17:11 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0303.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.