VDB
GCVE-VVD-MAGEIA-2021-486
GCVE-VVD-MAGEIA-2021-486
Advisory Published
Flatpak apps with direct access to AF_UNIX sockets such as those used by
Wayland, Pipewire or pipewire-pulse can trick portals and other host-OS
services into treating the Flatpak app as though it was an ordinary,
non-sandboxed host-OS process, by manipulating the VFS using recent
mount-related syscalls that are not blocked by Flatpak's denylist seccomp
filter, in order to substitute a crafted /.flatpak-info or make that file
disappear entirely.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | flatpak | 0 (affected), 1.10.5-1.mga8 (unaffected) | — |
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.