A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem. On system installs, the write happens as root.
There are two vulnerabilities in extract_extra_data .
extract_extra_data resolves files/extra inside the checked-out commit tree using GFile path operations, which follow symlinks. If the files entry in the OSTree commit is a symlink (e.g., files -> /tmp ), the downloaded extra-data blobs are written at the symlink target instead.
extract_extra_data writes downloaded blobs to files/extra/ where comes from xa.extra-data-sources in the commit metadata. g_file_get_child resolves .. components, so a name like ../metadata escapes the extra/ directory.
On system installs, this code is executed with root permission.
The issue has been patched in version 1.18.1 by commits:
c42326c "utils: Add flatpak_cp_a_at, a fd-based flatpak_cp_a variant"
12a30ec "utils: Make flatpak_cp_a a wrapper around flatpak_cp_a_at"
eef9aae "dir: Validate extra-data name in pull_extra_data_to_bytes"
4266256 "dir: Use chaseat in extract_extra_data to prevent path traversal"
e805016 "dir: Use chaseat in apply_extra_data to prevent path traversal"
For LTS operating system distributions, backports of these changes are available in the flatpak-1.16.x branch. Please note that cherry-picked libglnx changes "chase: Add internal glnx_chaseat_full for a strategic callback" and "chase: Add glnx_chase_and_mkdirat" are also required.
Avoid installing Flatpak extensions from untrusted sources.
Found by @swick after investigating a report from AISLE in cooperation with Red Hat.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
