{"schema_version":"1.7.5","id":"CVE-2021-41133","published":"2021-10-08T14:15:08.723Z","modified":"2026-07-09T10:11:35.501900Z","aliases":["GHSA-67h7-w3jq-vh4q"],"related":["ALEA-2021:4539","ALSA-2021:4042","SUSE-SU-2021:3472-1","SUSE-SU-2022:3284-1","SUSE-SU-2022:3439-1","openSUSE-SU-2021:1400-1","openSUSE-SU-2021:3472-1","openSUSE-SU-2024:11574-1"],"details":"Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior to 1.10.4 and 1.12.0, Flatpak apps with direct access to AF_UNIX sockets such as those used by Wayland, Pipewire or pipewire-pulse can trick portals and other host-OS services into treating the Flatpak app as though it was an ordinary, non-sandboxed host-OS process. They can do this by manipulating the VFS using recent mount-related syscalls that are not blocked by Flatpak's denylist seccomp filter, in order to substitute a crafted `/.flatpak-info` or make that file disappear entirely. Flatpak apps that act as clients for AF_UNIX sockets such as those used by Wayland, Pipewire or pipewire-pulse can escalate the privileges that the corresponding services will believe the Flatpak app has. Note that protocols that operate entirely over the D-Bus session bus (user bus), system bus or accessibility bus are not affected by this. This is due to the use of a proxy process `xdg-dbus-proxy`, whose VFS cannot be manipulated by the Flatpak app, when interacting with these buses. Patches exist for versions 1.10.4 and 1.12.0, and as of time of publication, a patch for version 1.8.2 is being planned. There are no workarounds aside from upgrading to a patched version.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/flatpak/flatpak","events":[{"introduced":"0"},{"fixed":"7ee022bfa5d06f5ea235a17add99cfeb9e82d8c8"},{"introduced":"649ad5fe49945b834da0d616a24400c41666048c"},{"fixed":"e4a41716d826cc7b11cba0da3452da096c8b4f9b"},{"introduced":"bcdc073041e0c93e15aa108b94cb7a39a79dcdf3"},{"fixed":"afb3575d3113a8491af25af3bbc7bcf1cb5b9b33"},{"fixed":"1330662f33a55e88bfe18e76de28b7922d91a999"},{"fixed":"26b12484eb8a6219b9e7aa287b298a894b2f34ca"},{"fixed":"462fca2c666e0cd2b60d6d2593a7216a83047aaf"},{"fixed":"4c34815784e9ffda5733225c7d95824f96375e36"},{"fixed":"89ae9fe74c6d445bb1b3a40e568d77cf5de47e48"},{"fixed":"9766ee05b1425db397d2cf23afd24c7f6146a69f"},{"fixed":"a10f52a7565c549612c92b8e736a6698a53db330"},{"fixed":"e26ac7586c392b5eb35ff4609fe232c52523b2cf"}],"database_specific":{"cpe":"cpe:2.3:a:flatpak:flatpak:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.8.2"},{"introduced":"1.10.0"},{"fixed":"1.10.4"},{"introduced":"1.11.1"},{"fixed":"1.12.1"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["1.11.2","1.12.0","1.10.3","1.11.3","1.11.1","1.10.2","1.10.1","1.10.0","1.8.0","1.7.3","1.7.2","1.7.1","1.6.2","1.6.1","1.6.0","1.5.2","1.5.1","1.5.0","1.4.0","1.3.4","1.3.3","1.3.2","1.3.1","1.3.0","1.2.1","1.2.0","1.1.3","1.1.2","1.1.1","1.1.0","1.0.3","1.0.2","1.0.1","1.0.0","0.99.3","0.99.2","0.99.1","0.11.8.3","0.11.8.2","0.11.8.1","0.11.8","0.11.7","0.11.6","0.11.5","0.11.4","0.11.3","0.11.2","0.11.1","0.10.2","0.10.1","0.10.0","0.9.99","0.9.98.2","0.9.98.1","0.9.98","0.9.12","0.9.11","0.9.10","0.9.9","0.9.8","0.9.7","0.9.6","0.9.5","0.9.4","0.9.3","0.9.2","0.9.1","0.8.1","0.8.0","0.6.14","0.6.13","0.6.12","0.6.11","0.6.10","0.6.9","0.6.8","0.6.7","0.6.6","0.6.5","0.6.4","0.6.3","0.6.2","0.6.1","0.6.0","0.5.2","0.5.1","0.5.0","0.4.13","0.4.12","0.4.11","0.4.10","0.4.9","0.4.8","0.4.7","0.4.6","0.4.5","0.4.4","0.4.3","0.4.2.1","0.4.2","0.4.1","0.4.0","0.3.6","0.3.5","0.3.4","0.3.3","0.3.2","0.3.1","0.3","0.2.1","0.2","0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-41133.json","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"61479616066351502827021815810250370741","length":4528},"id":"CVE-2021-41133-137e9545","signature_type":"Function","signature_version":"v1","source":"https://github.com/flatpak/flatpak/commit/e26ac7586c392b5eb35ff4609fe232c52523b2cf","target":{"file":"common/flatpak-run.c","function":"setup_seccomp"}},{"deprecated":false,"digest":{"line_hashes":["4724334225879976311471117484106403718","194995112989526175634640712191726920304","27047487972509731025761378941667157363","127959480553552999216692897581133910539","149725262348548741371578885411273821164","311752915716605336144744603351065432562","425383129524715248248505878896027117","230555913181258205454324462029096480513","159343556670961826859469546102215415876","174418748294864289117601730477975954840","15854124964998263237987521677018217358","273859984111820156498333161679708498564","50771528409135739446360476316050246715","228589148917655087891307914425490480149","62202718819061056914828441856285692587","203589004447366562652722352972549951501","153374246151843513788788449038046302174","136870487206867995887393854336751538227","63620577896542541414700980353664322370","239791117960607989996845175669273027339","293727190593737287385575774002548488290","267994865061715328140435891281611797818","288616061243822683627853685469421662107","311708903237832446535374075764489638254","58545996832719230416128378132683841818","194472222316619411219058299454943080426","145416432992512906419445395681813730896","102228759128634907032385177682272607969","316927798905693936088636599261489998151","194995112989526175634640712191726920304","295563790682390178648994199359788672558","6464364049780935852295494246075322686","290060387379342334419169775248165119435","40915048651048452828458914709435114468","157190698000436755414873710812720361564","58144154164164528063817355944148646112","289725933698978727012612296313532061136","86581713750054574471037547134984153843","190157355026833233689553141471330087288","241958725927313269859031474987126937859","299696461664737981268915700533216353083","188053357513928606679364907463052196661","115484920471859252011980810750830483314","21460207557478326608307561143369494311","184379532897056267407196887206061012314","331462179722718233898825905968849704349","51641069412997194519538233747890002543","101837067854513325656354013766934135648","112229933989855140433053843186185316800","43777985336737524678939350619975840019","101961086236674377531447391676003306549","21460207557478326608307561143369494311","184379532897056267407196887206061012314"],"threshold":0.9},"id":"CVE-2021-41133-1aea2591","signature_type":"Line","signature_version":"v1","source":"https://github.com/flatpak/flatpak/commit/e26ac7586c392b5eb35ff4609fe232c52523b2cf","target":{"file":"common/flatpak-run.c"}},{"deprecated":false,"digest":{"line_hashes":["292874080549319505669535040721616769930","289979036773457065837219046454024647774","334182435221815611659403687000781451201"],"threshold":0.9},"id":"CVE-2021-41133-24904614","signature_type":"Line","signature_version":"v1","source":"https://github.com/flatpak/flatpak/commit/26b12484eb8a6219b9e7aa287b298a894b2f34ca","target":{"file":"common/flatpak-run.c"}},{"deprecated":false,"digest":{"function_hash":"32462534173524075911709555975651922575","length":5303},"id":"CVE-2021-41133-36f53e30","signature_type":"Function","signature_version":"v1","source":"https://github.com/flatpak/flatpak/commit/462fca2c666e0cd2b60d6d2593a7216a83047aaf","target":{"file":"common/flatpak-run.c","function":"setup_seccomp"}},{"deprecated":false,"digest":{"function_hash":"176138903604538689866991033859709343505","length":5201},"id":"CVE-2021-41133-53e4daf3","signature_type":"Function","signature_version":"v1","source":"https://github.com/flatpak/flatpak/commit/4c34815784e9ffda5733225c7d95824f96375e36","target":{"file":"common/flatpak-run.c","function":"setup_seccomp"}},{"deprecated":false,"digest":{"function_hash":"246260823752652890623799432595773067790","length":5234},"id":"CVE-2021-41133-604ca01e","signature_type":"Function","signature_version":"v1","source":"https://github.com/flatpak/flatpak/commit/1330662f33a55e88bfe18e76de28b7922d91a999","target":{"file":"common/flatpak-run.c","function":"setup_seccomp"}},{"deprecated":false,"digest":{"line_hashes":["243356069132237602276796608365346512461","132853696152046682919140188082505777614","5447912673067045136651034019936086471","303359105953435315225660843192226432027"],"threshold":0.9},"id":"CVE-2021-41133-b36b0d00","signature_type":"Line","signature_version":"v1","source":"https://github.com/flatpak/flatpak/commit/1330662f33a55e88bfe18e76de28b7922d91a999","target":{"file":"common/flatpak-run.c"}},{"deprecated":false,"digest":{"line_hashes":["87134664724695983503595808360591199177","123318117091605583339771985557982327421","86939748348553514330436853630962931614","102667531024275203581307042771864062736"],"threshold":0.9},"id":"CVE-2021-41133-bd25aa38","signature_type":"Line","signature_version":"v1","source":"https://github.com/flatpak/flatpak/commit/462fca2c666e0cd2b60d6d2593a7216a83047aaf","target":{"file":"common/flatpak-run.c"}},{"deprecated":false,"digest":{"line_hashes":["333538579610011693680509417347934758090","315810809726265457439492125145570241368","131933848524763070254567068946949754402","328884496917528055780118370801943764550"],"threshold":0.9},"id":"CVE-2021-41133-c3df7ccb","signature_type":"Line","signature_version":"v1","source":"https://github.com/flatpak/flatpak/commit/a10f52a7565c549612c92b8e736a6698a53db330","target":{"file":"common/flatpak-run.c"}},{"deprecated":false,"digest":{"function_hash":"151143360952028898959330155444644965786","length":4904},"id":"CVE-2021-41133-ec9855cd","signature_type":"Function","signature_version":"v1","source":"https://github.com/flatpak/flatpak/commit/a10f52a7565c549612c92b8e736a6698a53db330","target":{"file":"common/flatpak-run.c","function":"setup_seccomp"}}],"vanir_signatures_modified":"2026-07-09T10:11:35Z"}}],"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R5656ONDP2MGKIJMKEC7N2NXCV27WGTC/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T5DKCYRC6MFSTFCUP4DELCOUUP3SFEFX/"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2021/10/26/9"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202312-12"},{"type":"ADVISORY","url":"https://www.debian.org/security/2021/dsa-4984"},{"type":"FIX","url":"https://github.com/flatpak/flatpak/commit/1330662f33a55e88bfe18e76de28b7922d91a999"},{"type":"FIX","url":"https://github.com/flatpak/flatpak/commit/26b12484eb8a6219b9e7aa287b298a894b2f34ca"},{"type":"FIX","url":"https://github.com/flatpak/flatpak/commit/462fca2c666e0cd2b60d6d2593a7216a83047aaf"},{"type":"FIX","url":"https://github.com/flatpak/flatpak/commit/4c34815784e9ffda5733225c7d95824f96375e36"},{"type":"FIX","url":"https://github.com/flatpak/flatpak/commit/89ae9fe74c6d445bb1b3a40e568d77cf5de47e48"},{"type":"FIX","url":"https://github.com/flatpak/flatpak/commit/9766ee05b1425db397d2cf23afd24c7f6146a69f"},{"type":"FIX","url":"https://github.com/flatpak/flatpak/commit/a10f52a7565c549612c92b8e736a6698a53db330"},{"type":"FIX","url":"https://github.com/flatpak/flatpak/commit/e26ac7586c392b5eb35ff4609fe232c52523b2cf"},{"type":"FIX","url":"https://github.com/flatpak/flatpak/security/advisories/GHSA-67h7-w3jq-vh4q"}],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"11.0"},{"last_affected":"11.0"}],"source":"CPE_STRING","vendor_product":"debian:debian_linux"},{"cpes":["cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"33"},{"last_affected":"33"},{"introduced":"34"},{"last_affected":"34"}],"source":"CPE_STRING","vendor_product":"fedoraproject:fedora"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}