QID 198605

Date Published: 2021-12-15

QID 198605: Ubuntu Security Notification for Flatpak Vulnerability (USN-5191-1)

Flatpak incorrectly handled certain af_unix sockets.

An attacker could use this to specially craft a flatpak application thatcould escape sandbox confinement.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5191-1 for updates and patch information.
    Vendor References

    CVEs related to QID 198605

    Software Advisories
    Advisory ID Software Component Link
    USN-5191-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5191-1