Flatpak 1.12 Released - Better Sub-Sandbox Handling To Benefit Steam

Written by Michael Larabel in Free Software on 8 October 2021 at 07:34 AM EDT. 38 Comments
Flatpak 1.12 was just released along with issuing Flatpak 1.10.4 to address a security vulnerability in the portal support.

Flatpak 1.10.4 arrived to fix a security vulnerability in the portal code that as a result of some new Linux kernel system calls not being blocked by SECCOMP rules, applications could create sub-sandboxes to confuse the sandboxing verification mechanisms of the portal. The vulnerability disclosure explained, "An anonymous reporter discovered that Flatpak apps with direct access to AF_UNIX sockets such as those used by Wayland, Pipewire or pipewire-pulse can trick portals and other host-OS services into treating the Flatpak app as though it was an ordinary, non-sandboxed host-OS process, by manipulating the VFS using recent mount-related syscalls that are not blocked by Flatpak's denylist seccomp filter, in order to substitute a crafted /.flatpak-info or make that file disappear entirely."

Flatpak 1.12 was also released this morning as the newest stable feature release. Notable with Flatpak 1.12 is better control around sub-sandboxes which most notably is being used by the Steam Flatpak.

More details on the Flatpak 1.12 update via GitHub.
Related News
About The Author
Michael Larabel

Michael Larabel is the principal author of Phoronix.com and founded the site in 2004 with a focus on enriching the Linux hardware experience. Michael has written more than 20,000 articles covering the state of Linux hardware support, Linux performance, graphics drivers, and other topics. Michael is also the lead developer of the Phoronix Test Suite, Phoromatic, and OpenBenchmarking.org automated benchmarking software. He can be followed via Twitter, LinkedIn, or contacted via MichaelLarabel.com.

Popular News This Week