Flatpak: Complete Sandbox Escape

36 points by eyberg


refi64

if I had a cent for each symlink-following-related CVE from this week, I'd have two cents, which isn't a lot, but further enforced my fear of having to deal with symlinks in security-sensitive contexts.

captn3m0

https://github.com/flatpak/flatpak/commit/4a678f463b455c585d38ac4cf4d994e7ce710f8e seems to the fix.

ianloic

I didn't think flatpak sandboxes were supposed to be a super strong security boundary...