<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T00:38:31.994585+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:6356</id>
    <title>ALSA-2024:6356 — Important: bubblewrap and flatpak security update</title>
    <updated>2026-10-03T00:38:32.355745+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: bubblewrap, AlmaLinux:9: flatpak, AlmaLinux:9: flatpak-devel, AlmaLinux:9: flatpak-libs, AlmaLinux:9: flatpak-selinux, AlmaLinux:9: flatpak-session-helper</p>
<p>Bubblewrap (/usr/bin/bwrap) is a core execution engine for unprivileged containers that works as a setuid binary on kernels without user namespaces.</p>
<p>Security Fix(es):</p>
<p>* flatpak: Access to files outside sandbox for apps using persistent= (--persist) (CVE-2024-42472)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:6356"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-06671</id>
    <title>bdu:2024-06671</title>
    <updated>2026-10-03T00:38:32.355821+00:00</updated>
    <content>bdu:2024-06671</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-06671"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0741</id>
    <title>certfr-2024-avi-0741 — De multiples vulnérabilités ont été découvertes dans les produits Juniper Secure Analytics. Certaines d'entre elles per…</title>
    <updated>2026-10-03T00:38:32.355838+00:00</updated>
    <content>certfr-2024-avi-0741</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0741"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2024-ul58888</id>
    <title>CLEANSTART-2024-UL58888 — Flatpak is a Linux application sandboxing and distribution framework</title>
    <updated>2026-10-03T00:38:32.355855+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: flatpak</p>
<p>Security vulnerability affects the flatpak package. Flatpak is a Linux application sandboxing and distribution framework.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2024-ul58888"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-226756</id>
    <title>EUVD-2026-226756</title>
    <updated>2026-10-03T00:38:32.355876+00:00</updated>
    <content>EUVD-2026-226756</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-226756"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-42472</id>
    <title>fkie_cve-2024-42472</title>
    <updated>2026-10-03T00:38:32.355888+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or compromised Flatpak app using persistent directories could access and write files outside of what it would otherwise have access to, which is an attack on integrity and confidentiality.</p>
<p>When `persistent=subdir` is used in the application permissions (represented as `--persist=subdir` in the command-line interface), that means that an application which otherwise doesn't have access to the real user home directory will see an empty home directory with a writeable subdirectory `subdir`. Behind the scenes, this directory is actually a bind mount and the data is stored in the per-application directory as `~/.var/app/$APPID/subdir`. This allows existing apps that are not aware of the per-application directory to still work as intended without general home directory access.</p>
<p>However, the application does have write access to the application directory `~/.var/app/$APPID` where this directory is stored. If the source directory for the `persistent`/`--persist` option is replaced by a symlink, then the next time the application is started, the bind mount will follow the symlink and mount whatever it points to into the sandbox.</p>
<p>Partial protection against this vulnerability can be provided by patching Flatpak using the patches in commits ceec2ffc and 98f79773. However, this leaves a race condition that could be exploited by two instances of a malicious app running…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-42472"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-2053</id>
    <title>OESA-2024-2053 — flatpak security update</title>
    <updated>2026-10-03T00:38:32.355932+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: flatpak, openEuler:20.03-LTS-SP4: flatpak, openEuler:22.03-LTS-SP1: flatpak, openEuler:24.03-LTS: flatpak, openEuler:22.03-LTS-SP4: flatpak</p>
<p>flatpak is a system for building, distributing and running sandboxed desktop applications on Linux. See https://wiki.gnome.org/Projects/SandboxedApps for more information.</p>
<p>Security Fix(es):</p>
<p>Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or compromised Flatpak app using persistent directories could access and write files outside of what it would otherwise have access to, which is an attack on integrity and confidentiality.</p>
<p>When `persistent=subdir` is used in the application permissions (represented as `--persist=subdir` in the command-line interface), that means that an application which otherwise doesn&amp;apos;t have access to the real user home directory will see an empty home directory with a writeable subdirectory `subdir`. Behind the scenes, this directory is actually a bind mount and the data is stored in the per-application directory as `~/.var/app/$APPID/subdir`. This allows existing apps that are not aware of the per-application directory to still work as intended without general home directory access.</p>
<p>However, the application does have write access to the application directory `~/.var/app/$APPID` where this directory is stored. If the source directory for the `persistent`/`--persist` option is replaced by a symlink, then the next time the application is started, the bind mount will follow the symlink and mount whatever it points to into the sandbox.</p>
<p>Partial protection against this vulnerabili…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-2053"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14269-1</id>
    <title>openSUSE-SU-2024:14269-1 — bubblewrap-0.10.0-1.1 on GA media</title>
    <updated>2026-10-03T00:38:32.355981+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>bubblewrap-0.10.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:14269-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:6355</id>
    <title>RHSA-2024:6355 — Red Hat Security Advisory: bubblewrap and flatpak security update</title>
    <updated>2026-10-03T00:38:32.355999+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>flatpak: Access to files outside sandbox for apps using persistent= (--persist)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:6355"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-ru-2025:0145-1</id>
    <title>SUSE-RU-2025:0145-1 — Recommended update for bubblewrap, flatpak, wayland-protocols</title>
    <updated>2026-10-03T00:38:32.356016+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Recommended update for bubblewrap, flatpak, wayland-protocols</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-ru-2025:0145-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-42472</id>
    <title>UBUNTU-CVE-2024-42472</title>
    <updated>2026-10-03T00:38:32.356031+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:18.04:LTS: flatpak, Ubuntu:20.04:LTS: flatpak, Ubuntu:22.04:LTS: flatpak, Ubuntu:24.04:LTS: flatpak</p>
<p>Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or compromised Flatpak app using persistent directories could access and write files outside of what it would otherwise have access to, which is an attack on integrity and confidentiality. When `persistent=subdir` is used in the application permissions (represented as `--persist=subdir` in the command-line interface), that means that an application which otherwise doesn't have access to the real user home directory will see an empty home directory with a writeable subdirectory `subdir`. Behind the scenes, this directory is actually a bind mount and the data is stored in the per-application directory as `~/.var/app/$APPID/subdir`. This allows existing apps that are not aware of the per-application directory to still work as intended without general home directory access. However, the application does have write access to the application directory `~/.var/app/$APPID` where this directory is stored. If the source directory for the `persistent`/`--persist` option is replaced by a symlink, then the next time the application is started, the bind mount will follow the symlink and mount whatever it points to into the sandbox. Partial protection against this vulnerability can be provided by patching Flatpak using the patches in commits ceec2ffc and 98f79773. However, this leaves a race condition that could be exploited by two instances of a malicious app running in…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-42472"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2059</id>
    <title>WID-SEC-W-2024-2059 — Red Hat Enterprise Linux (flatpak): Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-03T00:38:32.356073+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2059"/>
  </entry>
</feed>
