Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior to 1.10.8, 1.12.8, 1.14.4, and 1.15.4, if an attacker publishes a Flatpak app with elevated permissions, they can hide those permissions from users of the flatpak(1) command-line interface by setting other permissions to crafted values that contain non-printable control characters such as ESC. A fix is available in versions 1.10.8, 1.12.8, 1.14.4, and 1.15.4. As a workaround, use a GUI like GNOME Software rather than the command-line interface, or only install apps whose maintainers you trust.
{
"cwe_ids": [
"CWE-116"
],
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/28xxx/CVE-2023-28101.json"
}{
"cpe": "cpe:2.3:a:flatpak:flatpak:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.10.8"
},
{
"introduced": "1.12.0"
},
{
"fixed": "1.12.8"
},
{
"introduced": "1.14.0"
},
{
"fixed": "1.14.4"
},
{
"introduced": "1.15.0"
},
{
"fixed": "1.15.4"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}"2026-07-22T02:24:51Z"
[
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 9106.0,
"function_hash": "98317496632033256661265466576315244652"
},
"signature_version": "v1",
"source": "https://github.com/flatpak/flatpak/commit/6cac99dafe6003c8a4bd5666341c217876536869",
"id": "CVE-2023-28101-0559cceb",
"target": {
"function": "flatpak_builtin_remote_info",
"file": "app/flatpak-builtins-remote-info.c"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"200143383743434215888140092484954245204",
"134932841088178489408933855620621665259",
"42785232946839303943013070254508492448",
"248639240058941373838326857414859667836",
"210425379657882896508271818658722913172",
"206363753943954980768143191509206221554",
"226682960788814335396394996060500011191",
"167760726112222336177763253156143174830",
"108562966186620884911491227169479057506",
"194865340689831604041163166630392209980",
"335178801186303280760619562183931054515",
"150265430655286296888016861522072723251",
"200632762604652717435898801275610740621",
"218786253908557703664082462886103426230",
"9951918842360841040566303947350854037"
]
},
"signature_version": "v1",
"source": "https://github.com/flatpak/flatpak/commit/6cac99dafe6003c8a4bd5666341c217876536869",
"id": "CVE-2023-28101-09726794",
"target": {
"file": "app/flatpak-cli-transaction.c"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 662.0,
"function_hash": "266421281594058816605670517089742814187"
},
"signature_version": "v1",
"source": "https://github.com/flatpak/flatpak/commit/6cac99dafe6003c8a4bd5666341c217876536869",
"id": "CVE-2023-28101-0c041f28",
"target": {
"function": "print_perm_line",
"file": "app/flatpak-cli-transaction.c"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 279.0,
"function_hash": "83676187195856663889486154663099212764"
},
"signature_version": "v1",
"source": "https://github.com/flatpak/flatpak/commit/7fe63f2e8f1fd2dafc31d45154cf0b191ebec66c",
"id": "CVE-2023-28101-17e07c7f",
"target": {
"function": "main",
"file": "tests/test-context.c"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 2186.0,
"function_hash": "102216786370788545560568146470683322492"
},
"signature_version": "v1",
"source": "https://github.com/flatpak/flatpak/commit/7fe63f2e8f1fd2dafc31d45154cf0b191ebec66c",
"id": "CVE-2023-28101-1de09366",
"target": {
"function": "main",
"file": "tests/testcommon.c"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"113988872953227167942243030915917190850",
"290495882821496963461465407575215262887",
"75903582964128321867015124005014172326",
"141204140000216890584395740226975394682",
"138320897864461254577461857491011394230",
"223673362181811682937630103248139624752",
"89174099595981587270390036903751379174"
]
},
"signature_version": "v1",
"source": "https://github.com/flatpak/flatpak/commit/6cac99dafe6003c8a4bd5666341c217876536869",
"id": "CVE-2023-28101-1e87f182",
"target": {
"file": "tests/testcommon.c"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 166.0,
"function_hash": "299445439862710065703798122770541017546"
},
"signature_version": "v1",
"source": "https://github.com/flatpak/flatpak/commit/7fe63f2e8f1fd2dafc31d45154cf0b191ebec66c",
"id": "CVE-2023-28101-27566372",
"target": {
"function": "option_persist_cb",
"file": "common/flatpak-context.c"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 693.0,
"function_hash": "280107902565179321738268186621263119712"
},
"signature_version": "v1",
"source": "https://github.com/flatpak/flatpak/commit/7fe63f2e8f1fd2dafc31d45154cf0b191ebec66c",
"id": "CVE-2023-28101-2963ac48",
"target": {
"function": "context_parse_args",
"file": "tests/test-context.c"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 1834.0,
"function_hash": "337196697261893844330781563597543504751"
},
"signature_version": "v1",
"source": "https://github.com/flatpak/flatpak/commit/409e34187de2b2b2c4ef34c79f417be698830f6c",
"id": "CVE-2023-28101-37076b43",
"target": {
"function": "print_eol_info_message",
"file": "app/flatpak-cli-transaction.c"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 138.0,
"function_hash": "328637800992681520498540365503623621945"
},
"signature_version": "v1",
"source": "https://github.com/flatpak/flatpak/commit/7fe63f2e8f1fd2dafc31d45154cf0b191ebec66c",
"id": "CVE-2023-28101-3b2393ac",
"target": {
"function": "flatpak_context_set_persistent",
"file": "common/flatpak-context.c"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"104114656793530154120153117060992706596",
"303317275876767317416149063669727065841",
"87901124387130320469126507864222942579",
"277952238014697240089155174566377825931",
"77613890273526506024887710857840743133",
"284098854800885541947513019684976790023",
"290495882821496963461465407575215262887",
"75903582964128321867015124005014172326",
"290077499135511600270868684279138980179",
"117542728422898281963577748515686202079",
"24403814936658339249038310343284026900",
"247899984050338012842780009784131849070"
]
},
"signature_version": "v1",
"source": "https://github.com/flatpak/flatpak/commit/7fe63f2e8f1fd2dafc31d45154cf0b191ebec66c",
"id": "CVE-2023-28101-3e2b3169",
"target": {
"file": "tests/testcommon.c"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"155006999785824134465836086941146246122",
"199216186366817016312282548742431431923",
"26786200255410249400519413059853037750",
"146612480660437975378919373899987630090",
"102627059651289281008000368376081136699",
"24996951004819029998285516593383623564",
"124528288861149549148184135872108106213",
"46531957334213852234387953248240339258",
"134334702497063395505584876697084558245",
"111034971607489099003421789998728574482",
"86562878490339678706722542208603871234",
"307385942581636851421760390395396659153",
"33106447819374978664626043718650599010",
"300983387954169487505640063878261034897",
"46203858665496266975471184410495694144",
"112121388898861620009761147429095215031",
"338560913389850219977744903925697133503",
"245589890791922340415836555648611261664",
"208956313643911904864737270395873199426",
"198377457515869835579301983627128918752",
"249889814782555155735405865314963997594",
"32397611929248427871104078651828590451",
"132065110543975706805073312703532217115",
"101047239045142556502776769591718578833",
"111781982016334373641413908461224140123",
"56657036309970062812178597638707031211",
"130342666089229702679537533707578224202",
"128309006630560367280046563551671562437",
"323907344336077536382894438979377975772",
"26826666898084996324192466855047405931",
"312065476697201767230344435086277118850",
"18967939102208227780501671292661701773",
"250865224021642523294628153110891748589",
"188084228353937304311246201588205198996",
"137624201276753641183940008356400110141",
"72364044082136007161547199456172306745",
"147289943560436918488872815381688028291",
"101047239045142556502776769591718578833",
"61266481079021092688385580775072530184",
"14330446159871907499208434856943559234",
"131943292556892063053578707027060707162",
"307820990542766752611163919528286280032",
"33832364426070795336816975800923939367",
"189725311405950860973597897319376717822",
"117410523881418445026915498833364881282",
"280526953587961471821706679115229231374",
"295952040306705956788748109527531926603",
"42820485387733432793837105587693447580",
"234474700117994839630402101976252883331",
"180019273479703400327610921341142353367",
"298542725695441250736643961544169714700",
"52064808199443126612205387713984038203",
"137624201276753641183940008356400110141",
"96049480965728502679020548527734547551",
"290495882821496963461465407575215262887",
"75903582964128321867015124005014172326",
"294734521766932499456577558080850281396",
"167176539807387984190705595696665399802",
"251726288669511310650134067372756551830"
]
},
"signature_version": "v1",
"source": "https://github.com/flatpak/flatpak/commit/7fe63f2e8f1fd2dafc31d45154cf0b191ebec66c",
"id": "CVE-2023-28101-51b922b8",
"target": {
"file": "tests/test-context.c"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 12255.0,
"function_hash": "43381582198122235250446057530806491682"
},
"signature_version": "v1",
"source": "https://github.com/flatpak/flatpak/commit/7fe63f2e8f1fd2dafc31d45154cf0b191ebec66c",
"id": "CVE-2023-28101-535bd607",
"target": {
"function": "test_context_merge_fs",
"file": "tests/test-context.c"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"219719460563378701252791827380033668229",
"340262771402914429524377866426426818779",
"30015978217965262432908601488805237769",
"43332624775614035071276161985712646165",
"242163383541455439749163346402221136448",
"289582336688379530805358989851290533526",
"83668573149004489626400297005049386962",
"255514023715830401204115390313308033860"
]
},
"signature_version": "v1",
"source": "https://github.com/flatpak/flatpak/commit/409e34187de2b2b2c4ef34c79f417be698830f6c",
"id": "CVE-2023-28101-5c563c77",
"target": {
"file": "app/flatpak-cli-transaction.c"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 11231.0,
"function_hash": "137944268882017690942745013940790610603"
},
"signature_version": "v1",
"source": "https://github.com/flatpak/flatpak/commit/6cac99dafe6003c8a4bd5666341c217876536869",
"id": "CVE-2023-28101-6f6c7a7b",
"target": {
"function": "flatpak_builtin_info",
"file": "app/flatpak-builtins-info.c"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"237696741305838361088680568327819653304",
"161798019321744983468800977967882591789",
"236712826495496594431646212172445364354",
"157558373179105931605763426943124236868",
"60816415688850931622812041059030826818",
"289110087549291919659388658813845855448"
]
},
"signature_version": "v1",
"source": "https://github.com/flatpak/flatpak/commit/6cac99dafe6003c8a4bd5666341c217876536869",
"id": "CVE-2023-28101-834165df",
"target": {
"file": "common/flatpak-utils.c"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"202013176872676480371517077821903209601",
"166994284923334409771111731050049447478",
"286240022271065064078405686327225992209",
"158300289980843770976571713592809011413"
]
},
"signature_version": "v1",
"source": "https://github.com/flatpak/flatpak/commit/6cac99dafe6003c8a4bd5666341c217876536869",
"id": "CVE-2023-28101-8a3e91bd",
"target": {
"file": "app/flatpak-builtins-remote-info.c"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 5961.0,
"function_hash": "318508615663837988527364667916447370965"
},
"signature_version": "v1",
"source": "https://github.com/flatpak/flatpak/commit/7fe63f2e8f1fd2dafc31d45154cf0b191ebec66c",
"id": "CVE-2023-28101-9630d00f",
"target": {
"function": "flatpak_context_load_metadata",
"file": "common/flatpak-context.c"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"129999369140102921964759090927242249824",
"291134275429007838480502753107913670452",
"264754176911979665919322520327293988642",
"252130524096340217686655510176182853058",
"279609152502309633174947465894087452027",
"173233427893047199659899282216479685671",
"107795034814368349545815063545123276849",
"176120331439528995198689408701324050930",
"120005027179772936587722868544178224371",
"78789557279554497779766121401221108564",
"298733854343567872246092693839980975094",
"109432795576425244661604864506429726539",
"246512386412446147543951116607937494864",
"10302597441242161746071581548093551637",
"12949186262015582943865350351776360275",
"102958536349596809893432498269702819527",
"61090625042257944229028891038229136959",
"177714787697755184096606259077861710546",
"180825086710712822647244647612556046535",
"150883376783066570902663466896567295497",
"173217620172042256840204721299836471128",
"188379271139370714276254534481595998724",
"167894273508428465497154446566734013382",
"242873971394863410097636916663848170143",
"268137819152734727495408514058601046684",
"176993032295224202961433002511664614359",
"148139418378158113409565364938271306726",
"100481643610430598741679232793798197197"
]
},
"signature_version": "v1",
"source": "https://github.com/flatpak/flatpak/commit/7fe63f2e8f1fd2dafc31d45154cf0b191ebec66c",
"id": "CVE-2023-28101-c122d418",
"target": {
"file": "common/flatpak-context.c"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"311469946640281926913961058450371733907",
"82934720962789425100501155773148218215",
"176873334764744699133819791343830260026",
"30987434378147041835384680539253781427",
"328306979275333333485549866395607942100",
"36618225112401896829657736006603253787",
"75391581919271091796729810393028596848",
"191034069448169945130393815399452176894"
]
},
"signature_version": "v1",
"source": "https://github.com/flatpak/flatpak/commit/6cac99dafe6003c8a4bd5666341c217876536869",
"id": "CVE-2023-28101-d1fcaa0a",
"target": {
"file": "app/flatpak-builtins-info.c"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 2126.0,
"function_hash": "180580487374897914715716768846950067956"
},
"signature_version": "v1",
"source": "https://github.com/flatpak/flatpak/commit/6cac99dafe6003c8a4bd5666341c217876536869",
"id": "CVE-2023-28101-d59332d0",
"target": {
"function": "main",
"file": "tests/testcommon.c"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"70855743449551908724137039987516906084",
"110458351093461033488486507551688328500",
"175544884052511732389486025130615518058",
"18219322861749277380841634123788402992",
"308171192310232946985701815984627161464",
"289110087549291919659388658813845855448"
]
},
"signature_version": "v1",
"source": "https://github.com/flatpak/flatpak/commit/7fe63f2e8f1fd2dafc31d45154cf0b191ebec66c",
"id": "CVE-2023-28101-d8cd6ccf",
"target": {
"file": "common/flatpak-utils.c"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 1921.0,
"function_hash": "56989686088136025610324046738637128030"
},
"signature_version": "v1",
"source": "https://github.com/flatpak/flatpak/commit/7fe63f2e8f1fd2dafc31d45154cf0b191ebec66c",
"id": "CVE-2023-28101-e5e4dbd8",
"target": {
"function": "flatpak_context_parse_filesystem",
"file": "common/flatpak-context.c"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"271104510418220402174073867263648078563",
"126487714375393104795322008451835238274"
]
},
"signature_version": "v1",
"source": "https://github.com/flatpak/flatpak/commit/7fe63f2e8f1fd2dafc31d45154cf0b191ebec66c",
"id": "CVE-2023-28101-e87eac0b",
"target": {
"file": "common/flatpak-utils-private.h"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"236813703849462761127334756799909730225",
"272949934507000678808039295561168714083"
]
},
"signature_version": "v1",
"source": "https://github.com/flatpak/flatpak/commit/6cac99dafe6003c8a4bd5666341c217876536869",
"id": "CVE-2023-28101-f7419c5f",
"target": {
"file": "common/flatpak-utils-private.h"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-28101.json"