Announce: Flatpak releases 1.0.8 (security update)

Alexander Larsson alexl at redhat.com
Wed Mar 27 10:28:32 UTC 2019


Available here:
  https://github.com/flatpak/flatpak/releases

This release fixes CVE-2019-10063.

It has been discovered that the previous fix for CVE-2017-5226, which uses
seccomp to prevent sandboxed apps from using the (dangerous) TIOCSTI ioctl
was only incomplete on 64bit arches. This is now fixed.

* seccomp: Only compare the low 32bit of the TIOCSTI ioctl args.

$ sha256sum flatpak-1.0.8.tar.xz
1b1b419e3b2e8e75b18eb6442f0eb585fe402cea529729c15bbaf2622d746c3c
flatpak-1.0.8.tar.xz



-- 
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
 Alexander Larsson                                Red Hat, Inc
       alexl at redhat.com         alexander.larsson at gmail.com


More information about the Flatpak mailing list