Sebastian Wick aa19390539 revokefs: Avoid symlink path traversal in chmod()
Use glnx_chaseat to ensure that all the attacker-controlled paths end up
inside the basefd directory, and then AT_SYMLINK_NOFOLLOW to make sure
that the last path component won't escape from the basefd.

On kernels >= 6.6 we can now use fchmodat() with AT_SYMLINK_NOFOLLOW,
but on older kernels that didn't work, so if necessary fall back to
opening the file with O_NOFOLLOW and then calling fchmod() on it.

Because this is the last syscall that used the previous (flawed)
validation mechanism, we can now remove the validation helpers and be
sure that everything is using the glnx-chaseat()-based replacements.

[smcv: Separated from a larger commit for better reviewability]
Co-authored-by: Simon McVittie <smcv@collabora.com>
Resolves: https://github.com/flatpak/flatpak/security/advisories/GHSA-qrwq-7qwx-q9rp
2026-08-10 23:06:17 +02:00
…
…
2026-08-05 15:04:26 +00:00
…
…
…
…

Flatpak icon

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux.

See https://flatpak.org/ for more information.

Flatpak is available in the package repositories of most Linux distributions and can be installed from there. See https://flatpak.org/setup/ for quick setup instructions for many distributions.

Community discussion happens in #flatpak:matrix.org, on the mailing list, and on the Flathub Discourse.

Read documentation for Flatpak here.

Contributing

Flatpak welcomes contributions from anyone! Here are some ways you can help:

Hacking

See CONTRIBUTING.md

Related Projects

Here are some notable projects in the Flatpak ecosystem:

  • Flatseal: An app for managing permissions of Flatpak apps without using the CLI
  • Flat-manager: A tool for managing Flatpak repositories
S
Description
No description provided
Readme LGPL-2.1
133 MiB
0 Stars 1 Watchers 0 Forks
Languages
C 91.2%
Shell 6%
Meson 1.1%
Python 0.9%
Yacc 0.8%