<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 22:04:59 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:6356 — Important: bubblewrap and flatpak security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:6356</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: bubblewrap, AlmaLinux:9: flatpak, AlmaLinux:9: flatpak-devel, AlmaLinux:9: flatpak-libs, AlmaLinux:9: flatpak-selinux, AlmaLinux:9: flatpak-session-helper&lt;/p&gt;
&lt;p&gt;Bubblewrap (/usr/bin/bwrap) is a core execution engine for unprivileged containers that works as a setuid binary on kernels without user namespaces.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* flatpak: Access to files outside sandbox for apps using persistent= (--persist) (CVE-2024-42472)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: bubblewrap, AlmaLinux:9: flatpak, AlmaLinux:9: flatpak-devel, AlmaLinux:9: flatpak-libs, AlmaLinux:9: flatpak-selinux, AlmaLinux:9: flatpak-session-helper&lt;/p&gt;
&lt;p&gt;Bubblewrap (/usr/bin/bwrap) is a core execution engine for unprivileged containers that works as a setuid binary on kernels without user namespaces.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* flatpak: Access to files outside sandbox for apps using persistent= (--persist) (CVE-2024-42472)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:6356</guid>
    </item>
    <item>
      <title>bdu:2024-06671</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-06671</link>
      <description>bdu:2024-06671</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-06671</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0741 — De multiples vulnérabilités ont été découvertes dans les produits Juniper Secure Analytics. Certaines d'entre elles per…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0741</link>
      <description>certfr-2024-avi-0741</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0741</guid>
    </item>
    <item>
      <title>CLEANSTART-2024-UL58888 — Flatpak is a Linux application sandboxing and distribution framework</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2024-ul58888</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: flatpak&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the flatpak package. Flatpak is a Linux application sandboxing and distribution framework.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: flatpak&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the flatpak package. Flatpak is a Linux application sandboxing and distribution framework.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2024-ul58888</guid>
    </item>
    <item>
      <title>EUVD-2026-226756</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-226756</link>
      <description>EUVD-2026-226756</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-226756</guid>
    </item>
    <item>
      <title>fkie_cve-2024-42472</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-42472</link>
      <description>&lt;p&gt;Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or compromised Flatpak app using persistent directories could access and write files outside of what it would otherwise have access to, which is an attack on integrity and confidentiality.&lt;/p&gt;
&lt;p&gt;When `persistent=subdir` is used in the application permissions (represented as `--persist=subdir` in the command-line interface), that means that an application which otherwise doesn&amp;#39;t have access to the real user home directory will see an empty home directory with a writeable subdirectory `subdir`. Behind the scenes, this directory is actually a bind mount and the data is stored in the per-application directory as `~/.var/app/$APPID/subdir`. This allows existing apps that are not aware of the per-application directory to still work as intended without general home directory access.&lt;/p&gt;
&lt;p&gt;However, the application does have write access to the application directory `~/.var/app/$APPID` where this directory is stored. If the source directory for the `persistent`/`--persist` option is replaced by a symlink, then the next time the application is started, the bind mount will follow the symlink and mount whatever it points to into the sandbox.&lt;/p&gt;
&lt;p&gt;Partial protection against this vulnerability can be provided by patching Flatpak using the patches in commits ceec2ffc and 98f79773. However, this leaves a race condition that could be exploited by two instances of a malicious app running…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or compromised Flatpak app using persistent directories could access and write files outside of what it would otherwise have access to, which is an attack on integrity and confidentiality.&lt;/p&gt;
&lt;p&gt;When `persistent=subdir` is used in the application permissions (represented as `--persist=subdir` in the command-line interface), that means that an application which otherwise doesn&amp;#39;t have access to the real user home directory will see an empty home directory with a writeable subdirectory `subdir`. Behind the scenes, this directory is actually a bind mount and the data is stored in the per-application directory as `~/.var/app/$APPID/subdir`. This allows existing apps that are not aware of the per-application directory to still work as intended without general home directory access.&lt;/p&gt;
&lt;p&gt;However, the application does have write access to the application directory `~/.var/app/$APPID` where this directory is stored. If the source directory for the `persistent`/`--persist` option is replaced by a symlink, then the next time the application is started, the bind mount will follow the symlink and mount whatever it points to into the sandbox.&lt;/p&gt;
&lt;p&gt;Partial protection against this vulnerability can be provided by patching Flatpak using the patches in commits ceec2ffc and 98f79773. However, this leaves a race condition that could be exploited by two instances of a malicious app running…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-42472</guid>
    </item>
    <item>
      <title>OESA-2024-2053 — flatpak security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2053</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: flatpak, openEuler:20.03-LTS-SP4: flatpak, openEuler:22.03-LTS-SP1: flatpak, openEuler:24.03-LTS: flatpak, openEuler:22.03-LTS-SP4: flatpak&lt;/p&gt;
&lt;p&gt;flatpak is a system for building, distributing and running sandboxed desktop applications on Linux. See https://wiki.gnome.org/Projects/SandboxedApps for more information.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or compromised Flatpak app using persistent directories could access and write files outside of what it would otherwise have access to, which is an attack on integrity and confidentiality.&lt;/p&gt;
&lt;p&gt;When `persistent=subdir` is used in the application permissions (represented as `--persist=subdir` in the command-line interface), that means that an application which otherwise doesn&amp;amp;apos;t have access to the real user home directory will see an empty home directory with a writeable subdirectory `subdir`. Behind the scenes, this directory is actually a bind mount and the data is stored in the per-application directory as `~/.var/app/$APPID/subdir`. This allows existing apps that are not aware of the per-application directory to still work as intended without general home directory access.&lt;/p&gt;
&lt;p&gt;However, the application does have write access to the application directory `~/.var/app/$APPID` where this directory is stored. If the source directory for the `persistent`/`--persist` option is replaced by a symlink, then the next time the application is started, the bind mount will follow the symlink and mount whatever it points to into the sandbox.&lt;/p&gt;
&lt;p&gt;Partial protection against this vulnerabili…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: flatpak, openEuler:20.03-LTS-SP4: flatpak, openEuler:22.03-LTS-SP1: flatpak, openEuler:24.03-LTS: flatpak, openEuler:22.03-LTS-SP4: flatpak&lt;/p&gt;
&lt;p&gt;flatpak is a system for building, distributing and running sandboxed desktop applications on Linux. See https://wiki.gnome.org/Projects/SandboxedApps for more information.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or compromised Flatpak app using persistent directories could access and write files outside of what it would otherwise have access to, which is an attack on integrity and confidentiality.&lt;/p&gt;
&lt;p&gt;When `persistent=subdir` is used in the application permissions (represented as `--persist=subdir` in the command-line interface), that means that an application which otherwise doesn&amp;amp;apos;t have access to the real user home directory will see an empty home directory with a writeable subdirectory `subdir`. Behind the scenes, this directory is actually a bind mount and the data is stored in the per-application directory as `~/.var/app/$APPID/subdir`. This allows existing apps that are not aware of the per-application directory to still work as intended without general home directory access.&lt;/p&gt;
&lt;p&gt;However, the application does have write access to the application directory `~/.var/app/$APPID` where this directory is stored. If the source directory for the `persistent`/`--persist` option is replaced by a symlink, then the next time the application is started, the bind mount will follow the symlink and mount whatever it points to into the sandbox.&lt;/p&gt;
&lt;p&gt;Partial protection against this vulnerabili…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2053</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14269-1 — bubblewrap-0.10.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14269-1</link>
      <description>&lt;p&gt;bubblewrap-0.10.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;bubblewrap-0.10.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14269-1</guid>
    </item>
    <item>
      <title>RHSA-2024:6355 — Red Hat Security Advisory: bubblewrap and flatpak security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:6355</link>
      <description>&lt;p&gt;flatpak: Access to files outside sandbox for apps using persistent= (--persist)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;flatpak: Access to files outside sandbox for apps using persistent= (--persist)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:6355</guid>
    </item>
    <item>
      <title>SUSE-RU-2025:0145-1 — Recommended update for bubblewrap, flatpak, wayland-protocols</title>
      <link>https://cve.radiocsirt.org/vuln/suse-ru-2025:0145-1</link>
      <description>&lt;p&gt;Recommended update for bubblewrap, flatpak, wayland-protocols&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Recommended update for bubblewrap, flatpak, wayland-protocols&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-ru-2025:0145-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-42472</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-42472</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: flatpak, Ubuntu:20.04:LTS: flatpak, Ubuntu:22.04:LTS: flatpak, Ubuntu:24.04:LTS: flatpak&lt;/p&gt;
&lt;p&gt;Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or compromised Flatpak app using persistent directories could access and write files outside of what it would otherwise have access to, which is an attack on integrity and confidentiality. When `persistent=subdir` is used in the application permissions (represented as `--persist=subdir` in the command-line interface), that means that an application which otherwise doesn&amp;#39;t have access to the real user home directory will see an empty home directory with a writeable subdirectory `subdir`. Behind the scenes, this directory is actually a bind mount and the data is stored in the per-application directory as `~/.var/app/$APPID/subdir`. This allows existing apps that are not aware of the per-application directory to still work as intended without general home directory access. However, the application does have write access to the application directory `~/.var/app/$APPID` where this directory is stored. If the source directory for the `persistent`/`--persist` option is replaced by a symlink, then the next time the application is started, the bind mount will follow the symlink and mount whatever it points to into the sandbox. Partial protection against this vulnerability can be provided by patching Flatpak using the patches in commits ceec2ffc and 98f79773. However, this leaves a race condition that could be exploited by two instances of a malicious app running in…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: flatpak, Ubuntu:20.04:LTS: flatpak, Ubuntu:22.04:LTS: flatpak, Ubuntu:24.04:LTS: flatpak&lt;/p&gt;
&lt;p&gt;Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or compromised Flatpak app using persistent directories could access and write files outside of what it would otherwise have access to, which is an attack on integrity and confidentiality. When `persistent=subdir` is used in the application permissions (represented as `--persist=subdir` in the command-line interface), that means that an application which otherwise doesn&amp;#39;t have access to the real user home directory will see an empty home directory with a writeable subdirectory `subdir`. Behind the scenes, this directory is actually a bind mount and the data is stored in the per-application directory as `~/.var/app/$APPID/subdir`. This allows existing apps that are not aware of the per-application directory to still work as intended without general home directory access. However, the application does have write access to the application directory `~/.var/app/$APPID` where this directory is stored. If the source directory for the `persistent`/`--persist` option is replaced by a symlink, then the next time the application is started, the bind mount will follow the symlink and mount whatever it points to into the sandbox. Partial protection against this vulnerability can be provided by patching Flatpak using the patches in commits ceec2ffc and 98f79773. However, this leaves a race condition that could be exploited by two instances of a malicious app running in…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-42472</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-2059 — Red Hat Enterprise Linux (flatpak): Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2059</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2059</guid>
    </item>
  </channel>
</rss>
