<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for flatpak</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2022:3284-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2022-09-15T14:23:18Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2022-09-15T14:23:18Z</InitialReleaseDate>
    <CurrentReleaseDate>2022-09-15T14:23:18Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for flatpak</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for flatpak fixes the following issues:

- CVE-2021-41133: Fixed sandbox bypass via recent syscalls (bsc#1191507).
- CVE-2021-43860: Fixed metadata validation (bsc#1194610).
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">SUSE-2022-3284,SUSE-SLE-Product-HPC-15-SP1-ESPOS-2022-3284,SUSE-SLE-Product-HPC-15-SP1-LTSS-2022-3284,SUSE-SLE-Product-SLES-15-SP1-BCL-2022-3284,SUSE-SLE-Product-SLES-15-SP1-LTSS-2022-3284,SUSE-SLE-Product-SLES_SAP-15-SP1-2022-3284,SUSE-Storage-6-2022-3284</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2022/suse-su-20223284-1/</URL>
      <Description>Link for SUSE-SU-2022:3284-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2022-September/012249.html</URL>
      <Description>E-Mail link for SUSE-SU-2022:3284-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1191507</URL>
      <Description>SUSE Bug 1191507</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1194610</URL>
      <Description>SUSE Bug 1194610</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-21261/</URL>
      <Description>SUSE CVE CVE-2021-21261 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-41133/</URL>
      <Description>SUSE CVE CVE-2021-41133 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-43860/</URL>
      <Description>SUSE CVE CVE-2021-43860 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Enterprise Storage 6">
      <Branch Type="Product Name" Name="SUSE Enterprise Storage 6">
        <FullProductName ProductID="SUSE Enterprise Storage 6" CPE="cpe:/o:suse:ses:6">SUSE Enterprise Storage 6</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
        <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS" CPE="cpe:/o:suse:sle_hpc-espos:15:sp1">SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS">
        <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS" CPE="cpe:/o:suse:sle_hpc-ltss:15:sp1">SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 15 SP1-BCL">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 15 SP1-BCL">
        <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP1-BCL" CPE="cpe:/o:suse:sles_bcl:15:sp1">SUSE Linux Enterprise Server 15 SP1-BCL</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 15 SP1-LTSS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 15 SP1-LTSS">
        <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP1-LTSS" CPE="cpe:/o:suse:sles-ltss:15:sp1">SUSE Linux Enterprise Server 15 SP1-LTSS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 15 SP1">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 15 SP1">
        <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP1" CPE="cpe:/o:suse:sles_sap:15:sp1">SUSE Linux Enterprise Server for SAP Applications 15 SP1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="flatpak-1.2.3-150100.4.8.1">
      <FullProductName ProductID="flatpak-1.2.3-150100.4.8.1">flatpak-1.2.3-150100.4.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="flatpak-devel-1.2.3-150100.4.8.1">
      <FullProductName ProductID="flatpak-devel-1.2.3-150100.4.8.1">flatpak-devel-1.2.3-150100.4.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="flatpak-zsh-completion-1.2.3-150100.4.8.1">
      <FullProductName ProductID="flatpak-zsh-completion-1.2.3-150100.4.8.1">flatpak-zsh-completion-1.2.3-150100.4.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libflatpak0-1.2.3-150100.4.8.1">
      <FullProductName ProductID="libflatpak0-1.2.3-150100.4.8.1">libflatpak0-1.2.3-150100.4.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1">
      <FullProductName ProductID="typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1">typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1</FullProductName>
    </Branch>
    <Relationship ProductReference="flatpak-1.2.3-150100.4.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Enterprise Storage 6">
      <FullProductName ProductID="SUSE Enterprise Storage 6:flatpak-1.2.3-150100.4.8.1">flatpak-1.2.3-150100.4.8.1 as a component of SUSE Enterprise Storage 6</FullProductName>
    </Relationship>
    <Relationship ProductReference="flatpak-devel-1.2.3-150100.4.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Enterprise Storage 6">
      <FullProductName ProductID="SUSE Enterprise Storage 6:flatpak-devel-1.2.3-150100.4.8.1">flatpak-devel-1.2.3-150100.4.8.1 as a component of SUSE Enterprise Storage 6</FullProductName>
    </Relationship>
    <Relationship ProductReference="flatpak-zsh-completion-1.2.3-150100.4.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Enterprise Storage 6">
      <FullProductName ProductID="SUSE Enterprise Storage 6:flatpak-zsh-completion-1.2.3-150100.4.8.1">flatpak-zsh-completion-1.2.3-150100.4.8.1 as a component of SUSE Enterprise Storage 6</FullProductName>
    </Relationship>
    <Relationship ProductReference="libflatpak0-1.2.3-150100.4.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Enterprise Storage 6">
      <FullProductName ProductID="SUSE Enterprise Storage 6:libflatpak0-1.2.3-150100.4.8.1">libflatpak0-1.2.3-150100.4.8.1 as a component of SUSE Enterprise Storage 6</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Enterprise Storage 6">
      <FullProductName ProductID="SUSE Enterprise Storage 6:typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1">typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1 as a component of SUSE Enterprise Storage 6</FullProductName>
    </Relationship>
    <Relationship ProductReference="flatpak-1.2.3-150100.4.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:flatpak-1.2.3-150100.4.8.1">flatpak-1.2.3-150100.4.8.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="flatpak-devel-1.2.3-150100.4.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:flatpak-devel-1.2.3-150100.4.8.1">flatpak-devel-1.2.3-150100.4.8.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="flatpak-zsh-completion-1.2.3-150100.4.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:flatpak-zsh-completion-1.2.3-150100.4.8.1">flatpak-zsh-completion-1.2.3-150100.4.8.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libflatpak0-1.2.3-150100.4.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libflatpak0-1.2.3-150100.4.8.1">libflatpak0-1.2.3-150100.4.8.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1">typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="flatpak-1.2.3-150100.4.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:flatpak-1.2.3-150100.4.8.1">flatpak-1.2.3-150100.4.8.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="flatpak-devel-1.2.3-150100.4.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:flatpak-devel-1.2.3-150100.4.8.1">flatpak-devel-1.2.3-150100.4.8.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="flatpak-zsh-completion-1.2.3-150100.4.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:flatpak-zsh-completion-1.2.3-150100.4.8.1">flatpak-zsh-completion-1.2.3-150100.4.8.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libflatpak0-1.2.3-150100.4.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:libflatpak0-1.2.3-150100.4.8.1">libflatpak0-1.2.3-150100.4.8.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1">typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="flatpak-1.2.3-150100.4.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP1-BCL">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP1-BCL:flatpak-1.2.3-150100.4.8.1">flatpak-1.2.3-150100.4.8.1 as a component of SUSE Linux Enterprise Server 15 SP1-BCL</FullProductName>
    </Relationship>
    <Relationship ProductReference="flatpak-devel-1.2.3-150100.4.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP1-BCL">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP1-BCL:flatpak-devel-1.2.3-150100.4.8.1">flatpak-devel-1.2.3-150100.4.8.1 as a component of SUSE Linux Enterprise Server 15 SP1-BCL</FullProductName>
    </Relationship>
    <Relationship ProductReference="flatpak-zsh-completion-1.2.3-150100.4.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP1-BCL">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP1-BCL:flatpak-zsh-completion-1.2.3-150100.4.8.1">flatpak-zsh-completion-1.2.3-150100.4.8.1 as a component of SUSE Linux Enterprise Server 15 SP1-BCL</FullProductName>
    </Relationship>
    <Relationship ProductReference="libflatpak0-1.2.3-150100.4.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP1-BCL">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP1-BCL:libflatpak0-1.2.3-150100.4.8.1">libflatpak0-1.2.3-150100.4.8.1 as a component of SUSE Linux Enterprise Server 15 SP1-BCL</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP1-BCL">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP1-BCL:typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1">typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1 as a component of SUSE Linux Enterprise Server 15 SP1-BCL</FullProductName>
    </Relationship>
    <Relationship ProductReference="flatpak-1.2.3-150100.4.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP1-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP1-LTSS:flatpak-1.2.3-150100.4.8.1">flatpak-1.2.3-150100.4.8.1 as a component of SUSE Linux Enterprise Server 15 SP1-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="flatpak-devel-1.2.3-150100.4.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP1-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP1-LTSS:flatpak-devel-1.2.3-150100.4.8.1">flatpak-devel-1.2.3-150100.4.8.1 as a component of SUSE Linux Enterprise Server 15 SP1-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="flatpak-zsh-completion-1.2.3-150100.4.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP1-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP1-LTSS:flatpak-zsh-completion-1.2.3-150100.4.8.1">flatpak-zsh-completion-1.2.3-150100.4.8.1 as a component of SUSE Linux Enterprise Server 15 SP1-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libflatpak0-1.2.3-150100.4.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP1-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP1-LTSS:libflatpak0-1.2.3-150100.4.8.1">libflatpak0-1.2.3-150100.4.8.1 as a component of SUSE Linux Enterprise Server 15 SP1-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP1-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP1-LTSS:typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1">typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1 as a component of SUSE Linux Enterprise Server 15 SP1-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="flatpak-1.2.3-150100.4.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP1:flatpak-1.2.3-150100.4.8.1">flatpak-1.2.3-150100.4.8.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="flatpak-devel-1.2.3-150100.4.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP1:flatpak-devel-1.2.3-150100.4.8.1">flatpak-devel-1.2.3-150100.4.8.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="flatpak-zsh-completion-1.2.3-150100.4.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP1:flatpak-zsh-completion-1.2.3-150100.4.8.1">flatpak-zsh-completion-1.2.3-150100.4.8.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libflatpak0-1.2.3-150100.4.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP1:libflatpak0-1.2.3-150100.4.8.1">libflatpak0-1.2.3-150100.4.8.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP1:typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1">typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP1</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. A bug was discovered in the `flatpak-portal` service that can allow sandboxed applications to execute arbitrary code on the host system (a sandbox escape). This sandbox-escape bug is present in versions from 0.11.4 and before fixed versions 1.8.5 and 1.10.0. The Flatpak portal D-Bus service (`flatpak-portal`, also known by its D-Bus service name `org.freedesktop.portal.Flatpak`) allows apps in a Flatpak sandbox to launch their own subprocesses in a new sandbox instance, either with the same security settings as the caller or with more restrictive security settings. For example, this is used in Flatpak-packaged web browsers such as Chromium to launch subprocesses that will process untrusted web content, and give those subprocesses a more restrictive sandbox than the browser itself. In vulnerable versions, the Flatpak portal service passes caller-specified environment variables to non-sandboxed processes on the host system, and in particular to the `flatpak run` command that is used to launch the new sandbox instance. A malicious or compromised Flatpak app could set environment variables that are trusted by the `flatpak run` command, and use them to execute arbitrary code that is not in a sandbox. As a workaround, this vulnerability can be mitigated by preventing the `flatpak-portal` service from starting, but that mitigation will prevent many Flatpak apps from working correctly. This is fixed in versions 1.8.5 and 1.10.0.</Note>
    </Notes>
    <CVE>CVE-2021-21261</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Enterprise Storage 6:flatpak-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Enterprise Storage 6:flatpak-devel-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Enterprise Storage 6:flatpak-zsh-completion-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Enterprise Storage 6:libflatpak0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Enterprise Storage 6:typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:flatpak-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:flatpak-devel-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:flatpak-zsh-completion-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libflatpak0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:flatpak-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:flatpak-devel-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:flatpak-zsh-completion-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:libflatpak0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-BCL:flatpak-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-BCL:flatpak-devel-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-BCL:flatpak-zsh-completion-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-BCL:libflatpak0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-BCL:typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-LTSS:flatpak-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-LTSS:flatpak-devel-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-LTSS:flatpak-zsh-completion-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-LTSS:libflatpak0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-LTSS:typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP1:flatpak-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP1:flatpak-devel-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP1:flatpak-zsh-completion-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP1:libflatpak0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP1:typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.2</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2022/suse-su-20223284-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-21261.html</URL>
        <Description>CVE-2021-21261</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1180996</URL>
        <Description>SUSE Bug 1180996</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior to 1.10.4 and 1.12.0, Flatpak apps with direct access to AF_UNIX sockets such as those used by Wayland, Pipewire or pipewire-pulse can trick portals and other host-OS services into treating the Flatpak app as though it was an ordinary, non-sandboxed host-OS process. They can do this by manipulating the VFS using recent mount-related syscalls that are not blocked by Flatpak's denylist seccomp filter, in order to substitute a crafted `/.flatpak-info` or make that file disappear entirely. Flatpak apps that act as clients for AF_UNIX sockets such as those used by Wayland, Pipewire or pipewire-pulse can escalate the privileges that the corresponding services will believe the Flatpak app has. Note that protocols that operate entirely over the D-Bus session bus (user bus), system bus or accessibility bus are not affected by this. This is due to the use of a proxy process `xdg-dbus-proxy`, whose VFS cannot be manipulated by the Flatpak app, when interacting with these buses. Patches exist for versions 1.10.4 and 1.12.0, and as of time of publication, a patch for version 1.8.2 is being planned. There are no workarounds aside from upgrading to a patched version.</Note>
    </Notes>
    <CVE>CVE-2021-41133</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Enterprise Storage 6:flatpak-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Enterprise Storage 6:flatpak-devel-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Enterprise Storage 6:flatpak-zsh-completion-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Enterprise Storage 6:libflatpak0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Enterprise Storage 6:typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:flatpak-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:flatpak-devel-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:flatpak-zsh-completion-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libflatpak0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:flatpak-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:flatpak-devel-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:flatpak-zsh-completion-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:libflatpak0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-BCL:flatpak-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-BCL:flatpak-devel-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-BCL:flatpak-zsh-completion-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-BCL:libflatpak0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-BCL:typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-LTSS:flatpak-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-LTSS:flatpak-devel-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-LTSS:flatpak-zsh-completion-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-LTSS:libflatpak0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-LTSS:typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP1:flatpak-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP1:flatpak-devel-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP1:flatpak-zsh-completion-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP1:libflatpak0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP1:typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.6</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2022/suse-su-20223284-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-41133.html</URL>
        <Description>CVE-2021-41133</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1191507</URL>
        <Description>SUSE Bug 1191507</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1191937</URL>
        <Description>SUSE Bug 1191937</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn't properly validate that the permissions displayed to the user for an app at install time match the actual permissions granted to the app at runtime, in the case that there's a null byte in the metadata file of an app. Therefore apps can grant themselves permissions without the consent of the user. Flatpak shows permissions to the user during install by reading them from the "xa.metadata" key in the commit metadata. This cannot contain a null terminator, because it is an untrusted GVariant. Flatpak compares these permissions to the *actual* metadata, from the "metadata" file to ensure it wasn't lied to. However, the actual metadata contents are loaded in several places where they are read as simple C-style strings. That means that, if the metadata file includes a null terminator, only the content of the file from *before* the terminator gets compared to xa.metadata. Thus, any permissions that appear in the metadata file after a null terminator are applied at runtime but not shown to the user. So maliciously crafted apps can give themselves hidden permissions. Users who have Flatpaks installed from untrusted sources are at risk in case the Flatpak has a maliciously crafted metadata file, either initially or in an update. This issue is patched in versions 1.12.3 and 1.10.6. As a workaround, users can manually check the permissions of installed apps by checking the metadata file or the xa.metadata key on the commit metadata.</Note>
    </Notes>
    <CVE>CVE-2021-43860</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Enterprise Storage 6:flatpak-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Enterprise Storage 6:flatpak-devel-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Enterprise Storage 6:flatpak-zsh-completion-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Enterprise Storage 6:libflatpak0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Enterprise Storage 6:typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:flatpak-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:flatpak-devel-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:flatpak-zsh-completion-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:libflatpak0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:flatpak-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:flatpak-devel-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:flatpak-zsh-completion-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:libflatpak0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-BCL:flatpak-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-BCL:flatpak-devel-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-BCL:flatpak-zsh-completion-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-BCL:libflatpak0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-BCL:typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-LTSS:flatpak-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-LTSS:flatpak-devel-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-LTSS:flatpak-zsh-completion-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-LTSS:libflatpak0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-LTSS:typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP1:flatpak-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP1:flatpak-devel-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP1:flatpak-zsh-completion-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP1:libflatpak0-1.2.3-150100.4.8.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP1:typelib-1_0-Flatpak-1_0-1.2.3-150100.4.8.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2022/suse-su-20223284-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-43860.html</URL>
        <Description>CVE-2021-43860</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1194610</URL>
        <Description>SUSE Bug 1194610</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
