Alpine: multiple flatpak packages: security update to 1.14.6-r1

high Tenable Self-Hosted Container Security Plugin ID 427172

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. in
versions before 1.10.9, 1.12.9, 1.14.6, and 1.15.8, a malicious or compromised Flatpak app could execute
arbitrary code outside its sandbox. Normally, the `--command` argument of `flatpak run` expects to be
given a command to run in the specified Flatpak app, optionally along with some arguments. However it is
possible to instead pass `bwrap` arguments to `--command=`, such as `--bind`. It's possible to pass an
arbitrary `commandline` to the portal interface `org.freedesktop.portal.Background.RequestBackground` from
within a Flatpak app. When this is converted into a `--command` and arguments, it achieves the same effect
of passing arguments directly to `bwrap`, and thus can be used for a sandbox escape. The solution is to
pass the `--` argument to `bwrap`, which makes it stop processing options. This has been supported since
bubblewrap 0.3.0. All supported versions of Flatpak require at least that version of bubblewrap. xdg-
desktop-portal version 1.18.4 will mitigate this vulnerability by only allowing Flatpak apps to create
.desktop files for commands that do not start with --. The vulnerability is patched in 1.15.8, 1.10.9,
1.12.9, and 1.14.6. (CVE-2024-32462)

See Also

https://security.alpinelinux.org/vuln/CVE-2024-32462

Plugin Details

Severity: High

ID: 427172

Version: Revision 1.10

Type: Local

Published: 5/16/2025

Updated: 7/2/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.8

Percentile: 57.26

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2024-32462

CVSS v3

Risk Factor: High

Base Score: 8.4

Temporal Score: 7.3

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 4/18/2024

Reference Information

CVE: CVE-2024-32462