Sebastian Wick 70fdf20886 dir: Use chaseat in extract_extra_data to prevent path traversal
extract_extra_data() had two vulnerabilities:

1. It resolved "files/extra" using g_file_resolve_relative_path()
   which follows symlinks. A crafted OSTree commit with "files" as a
   symlink causes extra-data blobs to be written at the symlink target.
   On system installs this runs as root via the system helper, which
   validates signatures and checksums but not tree structure.

2. It used g_file_get_child(extradir, name) where name comes from
   xa.extra-data-sources in the commit metadata. Names containing ".."
   escape the extra/ directory. This is exploitable through the normal
   build flow: flatpak build-export rejects "/" but not "..".

Replace GFile path operations with fd-relative operations: open
"files" with glnx_chaseat using GLNX_CHASE_RESOLVE_NO_SYMLINKS,
create "extra" with glnx_chase_and_mkdirat using
GLNX_CHASE_RESOLVE_BENEATH, validate extra-data names against ".",
"..", and "/", and write with glnx_file_replace_contents_at anchored
to the extra directory fd.

[smcv: Open checkoutdir_dfd before trying to open its files subdir]
Co-authored-by: Simon McVittie <smcv@collabora.com>
Resolves: https://github.com/flatpak/flatpak/security/advisories/GHSA-fqx6-vh4p-42cg
2026-08-11 01:22:28 +02:00
2026-01-21 17:58:19 +00:00
2026-06-08 14:35:23 +02:00
2022-10-24 16:12:14 +01:00
2026-08-05 15:04:26 +00:00
2022-10-24 16:12:14 +01:00
2026-01-21 17:58:19 +00:00
2018-02-05 15:21:40 +00:00
2015-03-31 15:36:29 +01:00
2022-09-26 14:35:40 +01:00
2026-06-08 14:51:50 +02:00
2026-06-08 14:35:23 +02:00

Flatpak icon

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux.

See https://flatpak.org/ for more information.

Flatpak is available in the package repositories of most Linux distributions and can be installed from there. See https://flatpak.org/setup/ for quick setup instructions for many distributions.

Community discussion happens in #flatpak:matrix.org, on the mailing list, and on the Flathub Discourse.

Read documentation for Flatpak here.

Contributing

Flatpak welcomes contributions from anyone! Here are some ways you can help:

Hacking

See CONTRIBUTING.md

Related Projects

Here are some notable projects in the Flatpak ecosystem:

  • Flatseal: An app for managing permissions of Flatpak apps without using the CLI
  • Flat-manager: A tool for managing Flatpak repositories
S
Description
No description provided
Readme LGPL-2.1
119 MiB
0 Stars 1 Watchers 0 Forks
Languages
C 91.3%
Shell 5.8%
Meson 1.1%
Python 0.9%
Yacc 0.9%