{"id":"UBUNTU-CVE-2021-41133","details":"Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior to 1.10.4 and 1.12.0, Flatpak apps with direct access to AF_UNIX sockets such as those used by Wayland, Pipewire or pipewire-pulse can trick portals and other host-OS services into treating the Flatpak app as though it was an ordinary, non-sandboxed host-OS process. They can do this by manipulating the VFS using recent mount-related syscalls that are not blocked by Flatpak's denylist seccomp filter, in order to substitute a crafted `/.flatpak-info` or make that file disappear entirely. Flatpak apps that act as clients for AF_UNIX sockets such as those used by Wayland, Pipewire or pipewire-pulse can escalate the privileges that the corresponding services will believe the Flatpak app has. Note that protocols that operate entirely over the D-Bus session bus (user bus), system bus or accessibility bus are not affected by this. This is due to the use of a proxy process `xdg-dbus-proxy`, whose VFS cannot be manipulated by the Flatpak app, when interacting with these buses. Patches exist for versions 1.10.4 and 1.12.0, and as of time of publication, a patch for version 1.8.2 is being planned. There are no workarounds aside from upgrading to a patched version.","modified":"2026-04-22T14:58:18.624378Z","published":"2021-10-08T14:15:00Z","related":["USN-5191-1"],"upstream":["CVE-2021-41133"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-41133"},{"type":"REPORT","url":"https://github.com/flatpak/flatpak/security/advisories/GHSA-67h7-w3jq-vh4q"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-5191-1"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2021-41133"}],"affected":[{"package":{"name":"flatpak","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/flatpak@1.0.9-0ubuntu0.4?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.9-0ubuntu0.4"}]}],"versions":["0.8.7-5","0.10.0-1","0.10.0-2","0.10.1-1","0.10.2-1","0.10.2.1-1","0.10.2.1-2","0.10.3-1","0.11.1-0ubuntu1","0.11.3-2","0.11.3-3","0.11.7-0ubuntu0.1","1.0.1-0ubuntu0.1","1.0.6-0ubuntu0.1","1.0.7-0ubuntu0.18.04.1","1.0.8-0ubuntu0.18.04.1","1.0.9-0ubuntu0.1","1.0.9-0ubuntu0.2","1.0.9-0ubuntu0.3"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"flatpak","binary_version":"1.0.9-0ubuntu0.4"},{"binary_name":"flatpak-tests","binary_version":"1.0.9-0ubuntu0.4"},{"binary_name":"gir1.2-flatpak-1.0","binary_version":"1.0.9-0ubuntu0.4"},{"binary_name":"libflatpak0","binary_version":"1.0.9-0ubuntu0.4"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-41133.json"}},{"package":{"name":"flatpak","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/flatpak@1.6.5-0ubuntu0.4?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.5-0ubuntu0.4"}]}],"versions":["1.4.3-1","1.6.0-1","1.6.1-1","1.6.2-1","1.6.3-1","1.6.5-0ubuntu0.1","1.6.5-0ubuntu0.2","1.6.5-0ubuntu0.3"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"flatpak","binary_version":"1.6.5-0ubuntu0.4"},{"binary_name":"flatpak-tests","binary_version":"1.6.5-0ubuntu0.4"},{"binary_name":"gir1.2-flatpak-1.0","binary_version":"1.6.5-0ubuntu0.4"},{"binary_name":"libflatpak0","binary_version":"1.6.5-0ubuntu0.4"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-41133.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}