These had the *INTERFACE*.*METHOD* where the bus name should have been,
and a blank interface/method (meaning match any interface/method).
Because there's no bus name of that name on the AT-SPI bus, the only reason
why Flatpak apps were able to receive these broadcasts is that there was
a vulnerability in xdg-dbus-proxy, tracked as GHSA-r7hp-698j-2h6c. To
avoid regressions in Flatpak when the x-d-p vulnerability is fixed,
we need to correct these rules to have the intended bus name.
Signed-off-by: Simon McVittie <smcv@collabora.com>
Helps: https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-r7hp-698j-2h6c
The previous commit ensures that there isn't a heap overflow when
reading a huge delta path, but we should also just reject unreasonably
long paths. So we chose the arbitrary limit of PATH_MAX and assume that
anything beyond that arbitrary limit is probably abusive.
Helps: https://github.com/flatpak/flatpak/security/advisories/GHSA-jr92-2v97-wgvc
delta_read_data computed g_malloc(size + 1) where size came from the
delta stream. If size equals G_MAXSIZE, size + 1 wraps to zero and
g_malloc returns a minimal allocation, then g_input_stream_read_all
writes size bytes into it — a heap buffer overflow.
Resolves: https://github.com/flatpak/flatpak/security/advisories/GHSA-jr92-2v97-wgvc
The delta varint parser decoded into guint64 values which were then
passed to GLib I/O and allocation functions that take gsize. On 32-bit
systems where gsize is 32 bits this silently truncated the values.
Change the varint output and all delta operation size parameters to
gsize, and clamp the parsed value to G_MAXSIZE.
Resolves: https://github.com/flatpak/flatpak/security/advisories/GHSA-jr92-2v97-wgvc
Replace path-based flatpak_mkdir_p calls in flatpak_ensure_data_dir
with glnx_chase_and_mkdirat(RESOLVE_NO_SYMLINKS) to prevent an app
from replacing subdirectories of its data dir with symlinks between
runs and having them followed during the next sandbox setup.
In flatpak_run_setup_base_argv, replace path-based --bind args for
the app cache/data/config/tmp directories with --bind-fd using fds
obtained via glnx_chaseat(RESOLVE_NO_SYMLINKS), preventing both
symlink following and TOCTOU races when setting up these bind mounts.
Assisted-by: Claude:opus-4.6
Resolves: https://github.com/flatpak/flatpak/security/advisories/GHSA-8688-9x26-hhxj
A sandboxed app can replace ~/.var/app/$appid/.ld.so with a symlink,
causing regenerate_ld_cache to write files at an arbitrary location.
A concurrent app instance makes this a TOCTOU even after the initial
directory verification.
Replace all path-based operations with fd-based equivalents using
ld_so_dir_fd obtained via glnx_chase_and_mkdirat, and pass the
directory to bwrap via --bind-fd instead of --bind.
Assisted-by: Claude:opus-4.6
Resolves: https://github.com/flatpak/flatpak/security/advisories/GHSA-99wv-m8rp-g58x
This reverts commit 420ce91428.
Apparently we do depend on the session-set certificates in some
situations. We should fix that, but until someone puts in the effort to
do so, reverting this will at least unbreak things.
The commit metadata and ref validation checks in validate_commit_metadata()
and flatpak_dir_deploy() used G_IO_ERROR which gets downgraded to a generic
G_DBUS_ERROR_FAILED when crossing the system helper D-Bus boundary.
Use FLATPAK_ERROR_PERMISSION_DENIED so the error is preserved across D-Bus.
Every other access to index->manifests in the codebase checks for NULL
before dereferencing, but flatpak_image_collection_new did not. Add the
same guard to avoid a NULL pointer dereference if the OCI index has no
manifests array.
Instead of just blindly accepting any characters to make up the docker
registry domain, reject invalid domains (including ones which contain
e.g. '@', '#', and '?').
flatpak_docker_reference_parse() asserts that the regex always matches,
but inputs containing newlines cause the match to fail since the regex
is not compiled with G_REGEX_DOTALL. Return an error instead.
flatpak_permission_adds_permissions() had two bugs in its sorted-array
merge walk for comparing conditional permissions:
The function returned FALSE when a new conditional was not present in
the old set, which is the opposite of correct — a new conditional means
the permission can be granted under conditions it previously could not.
The loop also relied on reading a NULL sentinel past the end of the
GPtrArray, which is not NULL-terminated, causing an out-of-bounds read.
Replace with proper bounds-checked iteration that correctly detects new
conditionals as permission additions.
The close function would bail out on the first child stream close
failure, skipping the remaining children. Close all children and
propagate the first error.
The metadata, appstream, icon_64, and icon_128 fields are conditionally
initialized in flatpak_bundle_ref_new() depending on which keys exist in
the bundle metadata. The finalize function used g_bytes_unref() which is
not NULL-safe on older GLib versions.
The appdata XML parser uses g_assert() to validate parser state in
several places. Since the XML comes from the app's deploy directory and
is controlled by the package author, malformed XML triggers abort().
Replace all g_assert() calls with graceful handling: early returns when
there is no current component, NULL checks for content_rating, and
state resets for accumulated text and lang.
flatpak_oci_registry_mirror_blob uses self->token (destination registry)
instead of source_registry->token when downloading from the source. All
other parameters on the same call correctly use source_registry.
In practice the destination is always a local on-disk registry with no
token set, so this results in missing authentication when pulling from
authenticated source registries rather than a credential leak.
Downgrading an app or runtime previously failed outright for non root
users calling through the system helper, with an error stating that
updating to a specific commit requires root permissions.
Instead, allow downgrades through the system helper by introducing a new
flag that is set when the caller requests a downgrade.
New "org.freedesktop.Flatpak.app-downgrade" and "runtime-downgrade"
polkit actions are added that require auth_admin_keep for active users.
When bundle metadata validation fails after commit, the ref cleanup
via ostree_repo_set_ref_immediate could set error, then
flatpak_fail_error would try to set it again. Pass NULL for the
cleanup call since it's best-effort.
Handle NULL from g_key_file_get_string when a desktop file has no
Icon key, and from flatpak_dir_get_origin when deploy metadata is
missing or corrupted.
g_file_equal returns TRUE when paths are equal, so the != 0 check
was triggering a reload when the path was unchanged and keeping the
stale cache when the path changed to a different file.
g_file_replace can return NULL on failure (e.g. disk full). The
result was passed to g_converter_output_stream_new before the NULL
check. Move the check before use.
g_subprocess_new can return NULL if the fusermount binary is not
found. The NULL was passed directly to g_subprocess_wait_check,
causing a NULL dereference.
The setter used "summary-history-length" but the getter used
"sumary-history-length", so the configured value was never read
and the default was always used.
st_size is a 64-bit off_t but was truncated to gsize which is
32-bit on 32-bit platforms. A file larger than G_MAXSIZE - 1 would
cause size + 1 to overflow to 0, leading to a zero-size allocation
followed by an oversized read.
A symlink loop on the host filesystem would cause infinite recursion
and a stack overflow. Limit to 40 levels, matching the kernel's ELOOP
limit and the existing check in _exports_path_expose.
If a negated true conditional (e.g. `!true`) is evaludated, it should
always be considered false. However, the code would not do that
(continue to the next conditional), but instead falls through to the
evaluator which grants the permission, because
evaluator (condition) == !negated
... and the evaluator evaluates unknown conditions as false.
If we created an instance and we failed to get the PID of the instance,
we would still succeed. If one later calls flatpak_instance_is_running
or uses the result of flatpak_instance_get_pid with kill, it's possible
to terminate the entire process group (kill 0).
Let's just error out as early as possible to avoid those weird
half-initialized cases.
That unfortunately means we have to adjust a bunch of callers as well,
but fortunately, this only affects internal API.
glib-mkenums fails to generate proper nicks and strips away th non- and
no-. Fix those cases manually.
Also fix the header guard while at it.
Technically this is an API break, but the API does exactly the opposite
of what it promises, so if anyone depended on this, we probably would
have received a bug report. Let's take the risk and just change it.
If max_len is 0, either data1_len or data2_len is 0, which means we
would add -1 to either data1 or data2, making them point one byte before
the object which is UB.
This commit just changes match_bytes_at_end and match_bytes_at_start to
use index based comparisons which makes the code easier and less likely
to invoke UB.
_ostree_object_name_equal() derived both refs from parameter a,
so any two objects in the same hash bucket were considered equal.
This caused g_hash_table_add() to evict previously inserted objects
on hash collision, shrinking the reachable set below its true size
and potentially pruning objects that are still in use.