VDB

GCVE-VVD-MAGEIA-2023-115

GCVE-VVD-MAGEIA-2023-115
Advisory Published
Vulnetix · Advisory published October 31, 2023
If a malicious Flatpak app is run on a Linux virtual console such as /dev/tty1, it can copy text from the virtual console and paste it back into the virtual console's input buffer, from which the command might be run by the user's shell after the Flatpak app has exited. This is similar to CVE-2017-5226, but using the TIOCLINUX ioctl command instead of TIOCSTI. (CVE-2023-28100) Flatpak app with elevated permissions mayhide those permissions from users of the 'flatpak(1)' command-line interface by setting other permissions to crafted values that contain non-printable control characters such as 'ESC'. (CVE-2023-28101)

Affected Products

VendorProductVersionsPlatforms
Mageiaobconf0 (affected), 2.0.4-10.1.mga9 (unaffected)
Mageiaobconf-qt0 (affected), 0.16.2-1.1.mga9 (unaffected)
Mageiaopenbox0 (affected), 3.6.1-13.1.mga9 (unaffected)
Mageiatask-lxqt0 (affected), 1.3.0-2.1.mga9 (unaffected)
Mageiaflatpak0 (affected), 1.12.8-1.mga8 (unaffected), 0 (affected), 1.12.8-1.mga8 (unaffected)

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›