[CLSA-2025:1741291194] flatpak: Fix of CVE-2024-42472
Type:
security
Severity:
Important
Release date:
2025-03-06 19:59:59 UTC
Description:
- CVE-2024-42472: patch Flatpak to include the new --bind-fd option in bubblewrap to prevent symlink attacks on persistent directories
Updated packages:
  • flatpak-1.12.7-2.el9.tuxcare.els3.i686.rpm
    sha:7372684f0a78b4c4ef352f705b6bc3c50bedaa476812e9589db48f23c216380e
  • flatpak-1.12.7-2.el9.tuxcare.els3.x86_64.rpm
    sha:c791101a1b404b319f1fdf8b0c00f7d802abb01943c8073ce65b2dc69a81bee7
  • flatpak-devel-1.12.7-2.el9.tuxcare.els3.i686.rpm
    sha:506e644cea6256c5bdc039b7bb0f20a6fc9fc2043205a08667b142e092892cbb
  • flatpak-devel-1.12.7-2.el9.tuxcare.els3.x86_64.rpm
    sha:e476ff95117bb7950cddb9fd5811f2b3722ff261545231d72c71710c5d933284
  • flatpak-libs-1.12.7-2.el9.tuxcare.els3.i686.rpm
    sha:8dd6b1b02df4c94f2d6f66e699ef1bd9e69561d5a12756183501419f57cca376
  • flatpak-libs-1.12.7-2.el9.tuxcare.els3.x86_64.rpm
    sha:7d29f1fa0e748f942cc067e99db5e56789a3116ec169f77b95d0e5b7e3d1a425
  • flatpak-selinux-1.12.7-2.el9.tuxcare.els3.noarch.rpm
    sha:4ad8a514f35a5294fa79dddbe484fbf5eaa09e1980fee365d7c2596392703825
  • flatpak-session-helper-1.12.7-2.el9.tuxcare.els3.i686.rpm
    sha:0097b4c9e6e5020751b82ad2002a75d77f7942b4e4137281bd4f36108931b03c
  • flatpak-session-helper-1.12.7-2.el9.tuxcare.els3.x86_64.rpm
    sha:3343ad41e2e477997cee844c9d5bef565bc345c08cbaea92eb072946cb1d8c43
  • flatpak-tests-1.12.7-2.el9.tuxcare.els3.x86_64.rpm
    sha:010be031ffd0cdadf88302e64c09696cbc848a3d360618b9c3b1628797111d3b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.