CVE-2021-41133

Source
https://cve.org/CVERecord?id=CVE-2021-41133
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-41133.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-41133
Aliases
  • GHSA-67h7-w3jq-vh4q
Downstream
Related
Published
2021-10-08T14:15:08Z
Modified
2026-07-09T10:11:35Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior to 1.10.4 and 1.12.0, Flatpak apps with direct access to AF_UNIX sockets such as those used by Wayland, Pipewire or pipewire-pulse can trick portals and other host-OS services into treating the Flatpak app as though it was an ordinary, non-sandboxed host-OS process. They can do this by manipulating the VFS using recent mount-related syscalls that are not blocked by Flatpak's denylist seccomp filter, in order to substitute a crafted /.flatpak-info or make that file disappear entirely. Flatpak apps that act as clients for AF_UNIX sockets such as those used by Wayland, Pipewire or pipewire-pulse can escalate the privileges that the corresponding services will believe the Flatpak app has. Note that protocols that operate entirely over the D-Bus session bus (user bus), system bus or accessibility bus are not affected by this. This is due to the use of a proxy process xdg-dbus-proxy, whose VFS cannot be manipulated by the Flatpak app, when interacting with these buses. Patches exist for versions 1.10.4 and 1.12.0, and as of time of publication, a patch for version 1.8.2 is being planned. There are no workarounds aside from upgrading to a patched version.

Database specific
{
    "unresolved_ranges": [
        {
            "cpes": [
                "cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "introduced": "11.0"
                },
                {
                    "last_affected": "11.0"
                }
            ],
            "source": "CPE_STRING",
            "vendor_product": "debian:debian_linux"
        },
        {
            "cpes": [
                "cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*",
                "cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "introduced": "33"
                },
                {
                    "last_affected": "33"
                },
                {
                    "introduced": "34"
                },
                {
                    "last_affected": "34"
                }
            ],
            "source": "CPE_STRING",
            "vendor_product": "fedoraproject:fedora"
        }
    ]
}
References

Affected packages

Git / github.com/flatpak/flatpak

Affected ranges

Type
GIT
Repo
https://github.com/flatpak/flatpak
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:flatpak:flatpak:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.8.2"
        },
        {
            "introduced": "1.10.0"
        },
        {
            "fixed": "1.10.4"
        },
        {
            "introduced": "1.11.1"
        },
        {
            "fixed": "1.12.1"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.1
0.10.0
0.10.1
0.10.2
0.11.1
0.11.2
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.8.1
0.11.8.2
0.11.8.3
0.2
0.2.1
0.3
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.2
0.4.2.1
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.2
0.6.0
0.6.1
0.6.10
0.6.11
0.6.12
0.6.13
0.6.14
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.8.0
0.8.1
0.9.1
0.9.10
0.9.11
0.9.12
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
0.9.98
0.9.98.1
0.9.98.2
0.9.99
0.99.1
0.99.2
0.99.3
1.*
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.11.1
1.11.2
1.11.3
1.12.0
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.7.3
1.8.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-41133.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "61479616066351502827021815810250370741",
            "length": 4528
        },
        "id": "CVE-2021-41133-137e9545",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/flatpak/flatpak/commit/e26ac7586c392b5eb35ff4609fe232c52523b2cf",
        "target": {
            "file": "common/flatpak-run.c",
            "function": "setup_seccomp"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "4724334225879976311471117484106403718",
                "194995112989526175634640712191726920304",
                "27047487972509731025761378941667157363",
                "127959480553552999216692897581133910539",
                "149725262348548741371578885411273821164",
                "311752915716605336144744603351065432562",
                "425383129524715248248505878896027117",
                "230555913181258205454324462029096480513",
                "159343556670961826859469546102215415876",
                "174418748294864289117601730477975954840",
                "15854124964998263237987521677018217358",
                "273859984111820156498333161679708498564",
                "50771528409135739446360476316050246715",
                "228589148917655087891307914425490480149",
                "62202718819061056914828441856285692587",
                "203589004447366562652722352972549951501",
                "153374246151843513788788449038046302174",
                "136870487206867995887393854336751538227",
                "63620577896542541414700980353664322370",
                "239791117960607989996845175669273027339",
                "293727190593737287385575774002548488290",
                "267994865061715328140435891281611797818",
                "288616061243822683627853685469421662107",
                "311708903237832446535374075764489638254",
                "58545996832719230416128378132683841818",
                "194472222316619411219058299454943080426",
                "145416432992512906419445395681813730896",
                "102228759128634907032385177682272607969",
                "316927798905693936088636599261489998151",
                "194995112989526175634640712191726920304",
                "295563790682390178648994199359788672558",
                "6464364049780935852295494246075322686",
                "290060387379342334419169775248165119435",
                "40915048651048452828458914709435114468",
                "157190698000436755414873710812720361564",
                "58144154164164528063817355944148646112",
                "289725933698978727012612296313532061136",
                "86581713750054574471037547134984153843",
                "190157355026833233689553141471330087288",
                "241958725927313269859031474987126937859",
                "299696461664737981268915700533216353083",
                "188053357513928606679364907463052196661",
                "115484920471859252011980810750830483314",
                "21460207557478326608307561143369494311",
                "184379532897056267407196887206061012314",
                "331462179722718233898825905968849704349",
                "51641069412997194519538233747890002543",
                "101837067854513325656354013766934135648",
                "112229933989855140433053843186185316800",
                "43777985336737524678939350619975840019",
                "101961086236674377531447391676003306549",
                "21460207557478326608307561143369494311",
                "184379532897056267407196887206061012314"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2021-41133-1aea2591",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/flatpak/flatpak/commit/e26ac7586c392b5eb35ff4609fe232c52523b2cf",
        "target": {
            "file": "common/flatpak-run.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "292874080549319505669535040721616769930",
                "289979036773457065837219046454024647774",
                "334182435221815611659403687000781451201"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2021-41133-24904614",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/flatpak/flatpak/commit/26b12484eb8a6219b9e7aa287b298a894b2f34ca",
        "target": {
            "file": "common/flatpak-run.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "32462534173524075911709555975651922575",
            "length": 5303
        },
        "id": "CVE-2021-41133-36f53e30",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/flatpak/flatpak/commit/462fca2c666e0cd2b60d6d2593a7216a83047aaf",
        "target": {
            "file": "common/flatpak-run.c",
            "function": "setup_seccomp"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "176138903604538689866991033859709343505",
            "length": 5201
        },
        "id": "CVE-2021-41133-53e4daf3",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/flatpak/flatpak/commit/4c34815784e9ffda5733225c7d95824f96375e36",
        "target": {
            "file": "common/flatpak-run.c",
            "function": "setup_seccomp"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "246260823752652890623799432595773067790",
            "length": 5234
        },
        "id": "CVE-2021-41133-604ca01e",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/flatpak/flatpak/commit/1330662f33a55e88bfe18e76de28b7922d91a999",
        "target": {
            "file": "common/flatpak-run.c",
            "function": "setup_seccomp"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "243356069132237602276796608365346512461",
                "132853696152046682919140188082505777614",
                "5447912673067045136651034019936086471",
                "303359105953435315225660843192226432027"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2021-41133-b36b0d00",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/flatpak/flatpak/commit/1330662f33a55e88bfe18e76de28b7922d91a999",
        "target": {
            "file": "common/flatpak-run.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "87134664724695983503595808360591199177",
                "123318117091605583339771985557982327421",
                "86939748348553514330436853630962931614",
                "102667531024275203581307042771864062736"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2021-41133-bd25aa38",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/flatpak/flatpak/commit/462fca2c666e0cd2b60d6d2593a7216a83047aaf",
        "target": {
            "file": "common/flatpak-run.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "333538579610011693680509417347934758090",
                "315810809726265457439492125145570241368",
                "131933848524763070254567068946949754402",
                "328884496917528055780118370801943764550"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2021-41133-c3df7ccb",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/flatpak/flatpak/commit/a10f52a7565c549612c92b8e736a6698a53db330",
        "target": {
            "file": "common/flatpak-run.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "151143360952028898959330155444644965786",
            "length": 4904
        },
        "id": "CVE-2021-41133-ec9855cd",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/flatpak/flatpak/commit/a10f52a7565c549612c92b8e736a6698a53db330",
        "target": {
            "file": "common/flatpak-run.c",
            "function": "setup_seccomp"
        }
    }
]
vanir_signatures_modified
"2026-07-09T10:11:35Z"