It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-17 package apport hooks, it could expose private data to other local users.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "20.10"
},
{
"introduced": "0"
},
{
"last_affected": "21.10"
},
{
"introduced": "0"
},
{
"last_affected": "17"
}
]
}