Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. Versions prior to 1.10.8, 1.12.8, 1.14.4, and 1.15.4 contain a vulnerability similar to CVE-2017-5226, but using the `TIOCLINUX` ioctl command instead of `TIOCSTI`. If a Flatpak app is run on a Linux virtual console such as `/dev/tty1`, it can copy text from the virtual console and paste it into the command buffer, from which the command might be run after the Flatpak app has exited. Ordinary graphical terminal emulators like xterm, gnome-terminal and Konsole are unaffected. This vulnerability is specific to the Linux virtual consoles `/dev/tty1`, `/dev/tty2` and so on. A patch is available in versions 1.10.8, 1.12.8, 1.14.4, and 1.15.4. As a workaround, don't run Flatpak on a Linux virtual console. Flatpak is primarily designed to be used in a Wayland or X11 graphical environment.
                
            Metrics
Affected Vendors & Products
References
        History
                    Tue, 15 Oct 2024 17:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-03-16T15:51:32.037Z
Updated: 2025-02-13T16:45:39.112Z
Reserved: 2023-03-10T18:34:29.226Z
Link: CVE-2023-28100
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-02T12:30:23.948Z
 NVD
                        NVD
                    Status : Modified
Published: 2023-03-16T16:15:12.553
Modified: 2024-11-21T07:54:24.163
Link: CVE-2023-28100
 Redhat
                        Redhat