Gnoppix Security has released an urgent update for the Flatpak package, fixing multiple vulnerabilities that allow sandbox escape and arbitrary code execution. Systems running Gnoppix 24/25 (oldstable) and Gnoppix 26 (stable) must upgrade immediately to prevent exploitation.
Critical Flaws in Flatpak
The advisory, GSA-6432-1, addresses two primary issues:
- Sandbox bypass via maliciously crafted
.flatpakreffiles that bypass runtime security checks. - Code injection through improper handling of exported metadata, enabling attackers to run arbitrary commands on the host.
An attacker can fully escape the Flatpak sandbox and gain access to the underlying operating system.
Affected Releases and Fixed Versions
- Gnoppix 24/25 (oldstable) – Fixed in version 1.14.4-1+deb12u1
- Gnoppix 26 (stable) – Fixed in version 1.14.6-1
The testing distribution Gnoppix 27 will receive the update when it becomes stable.
Immediate Action Required
All users must upgrade flatpak now using the standard package manager commands. - Please update your systems.