mirror of
https://github.com/flatpak/flatpak.git
synced 2026-09-29 00:27:56 -04:00
A sandboxed app can replace ~/.var/app/$appid/.ld.so with a symlink, causing regenerate_ld_cache to write files at an arbitrary location. A concurrent app instance makes this a TOCTOU even after the initial directory verification. Replace all path-based operations with fd-based equivalents using ld_so_dir_fd obtained via glnx_chase_and_mkdirat, and pass the directory to bwrap via --bind-fd instead of --bind. Assisted-by: Claude:opus-4.6 Resolves: https://github.com/flatpak/flatpak/security/advisories/GHSA-99wv-m8rp-g58x