I usually trust my distro repos without checking. Can the same be applied to flathub without much worry?

You are viewing a single thread.
View all comments
-20 points

I’d recommend that you stop using Flatpak immediately, it’s a horrific security nightmare.

https://flatkill.org

permalink
report
reply
18 points
  1. It looks like this website hasn’t been updated since 2020.
  2. Most of the things here are (probably) patched, besides many developers have claimed the right to update their own apps, and those apps are verified (a new feature created in 2023).
  3. Before uploading an app that requires home or host filesystem access, developers must specify the reason.
  4. Ever since xdg portals became a thing, I have seen more apps switch to them
permalink
report
parent
reply
-4 points

The fact that the website hasn’t been updated since 2020 and still has an open CVE shines the light on Flatpak’s attention to security.

Regarding point 3, if that’s true, then why are all of the most-dowloaded packages on Flathub mislabelled as ‘sandboxed’ when they have full write access to a user’s home directory? That isn’t a sandbox.

Flatpak currently has a 7.2 vulnerability that has gone unaddressed since 2017. The maximum vulnerability rating is a 9, so this is quite major.

https://www.cvedetails.com/vulnerability-list.php?vendor_id=16613&product_id=&version_id=&page=1&hasexp=0&opdos=0&opec=0&opov=0&opcsrf=0&opgpriv=0&opsqli=0&opxss=0&opdirt=0&opmemc=0&ophttprs=0&opbyp=0&opfileinc=0&opginf=0&cvssscoremin=3&cvssscoremax=0&year=0&month=0&cweid=0&order=1&trc=9&sha=14fe55bfe41eaaaaca8e742bde18bc6938f88a3e

permalink
report
parent
reply
11 points

Maybe you should have read the entries in the link you posted

Flatpak currently has a 7.2 vulnerability that has gone unaddressed since 2017.

Text about the 7.2 vulnerability from 2017:

In Flatpak before 0.8.7

That version was tagged in git on July 20th, 2017

permalink
report
parent
reply

Linux

!linux@lemmy.ml

Create post

From Wikipedia, the free encyclopedia

Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word “Linux” in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

Rules

  • Posts must be relevant to operating systems running the Linux kernel. GNU/Linux or otherwise.
  • No misinformation
  • No NSFW content
  • No hate speech, bigotry, etc

Related Communities

Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

Community stats

  • 7.5K

    Monthly active users

  • 6.6K

    Posts

  • 180K

    Comments