[CLSA-2025:1741125454] bubblewrap: Fix of CVE-2024-42472
Type:
security
Severity:
Important
Release date:
2025-03-04 21:57:39 UTC
Description:
- fix CVE-2024-42472 in flatpak by adding --bind-fd and --ro-bind-fd options in in bubblewrap, enabling race-free bind mounts using an O_PATH file descriptor instead of a direct path
Updated packages:
  • bubblewrap-0.4.1-6.el9.tuxcare.els1.x86_64.rpm
    sha:9d290b41a14fd7577cfa59cf04ae166d1094a79f17a3a9ccbfc6bb08ee5bd3cf
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.