Red Hat Customer Portal

Skip to main content

Main Navigation

  • Products & Services
    • Back
    • View All Products
    • Infrastructure and Management
      • Back
      • Red Hat Enterprise Linux
      • Red Hat Virtualization
      • Red Hat Identity Management
      • Red Hat Directory Server
      • Red Hat Certificate System
      • Red Hat Satellite
      • Red Hat Subscription Management
      • Red Hat Update Infrastructure
      • Red Hat Insights
      • Red Hat Ansible Automation Platform
    • Cloud Computing
      • Back
      • Red Hat CloudForms
      • Red Hat OpenStack Platform
      • Red Hat OpenShift Container Platform
      • Red Hat OpenShift Online
      • Red Hat OpenShift Dedicated
      • Red Hat Advanced Cluster Management for Kubernetes
      • Red Hat Quay
      • Red Hat CodeReady Workspaces
    • Storage
      • Back
      • Red Hat Gluster Storage
      • Red Hat Hyperconverged Infrastructure
      • Red Hat Ceph Storage
      • Red Hat Openshift Container Storage
    • Runtimes
      • Back
      • Red Hat Runtimes
      • Red Hat JBoss Enterprise Application Platform
      • Red Hat Data Grid
      • Red Hat JBoss Web Server
      • Red Hat Single Sign On
      • Red Hat support for Spring Boot
      • Red Hat build of Node.js
      • Red Hat build of Thorntail
      • Red Hat build of Eclipse Vert.x
      • Red Hat build of OpenJDK
      • Red Hat build of Quarkus
      • Red Hat CodeReady Studio
    • Integration and Automation
      • Back
      • Red Hat Integration
      • Red Hat Fuse
      • Red Hat AMQ
      • Red Hat 3scale API Management
      • Red Hat JBoss Data Virtualization
      • Red Hat Process Automation
      • Red Hat Process Automation Manager
      • Red Hat Decision Manager
    • Support
    • Production Support
    • Development Support
    • Product Life Cycles
    • Documentation
    • Red Hat Enterprise Linux
    • Red Hat JBoss Enterprise Application Platform
    • Red Hat OpenStack Platform
    • Red Hat OpenShift Container Platform
    • Services
    • Consulting
    • Technical Account Management
    • Training & Certifications
    • Ecosystem Catalog
    • Partner Resources
    • Red Hat in the Public Cloud
  • Tools
    • Back
    • Red Hat Insights
    • Tools
    • Troubleshoot a product issue
    • Packages
    • Errata
    • Customer Portal Labs
    • Explore Labs
    • Configuration
    • Deployment
    • Security
    • Troubleshooting
  • Security
    • Back
    • Product Security Center
    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Security Labs
    • Resources
    • Overview
    • Security Blog
    • Security Measurement
    • Severity Ratings
    • Backporting Policies
    • Product Signing (GPG) Keys
  • Community
    • Back
    • Customer Portal Community
    • Discussions
    • Blogs
    • Private Groups
    • Community Activity
    • Customer Events
    • Red Hat Convergence
    • Red Hat Summit
    • Stories
    • Red Hat Subscription Value
    • You Asked. We Acted.
    • Open Source Communities
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Account
    • Back
    • Log In
    • Register
    • Red Hat Account Number:
    • Account Details
    • User Management
    • Account Maintenance
    • My Profile
    • Notifications
    • Help
    • Log Out
  • Language
    • Back
    • English
    • 한국어
    • 日本語
    • 中文 (中国)
Red Hat Customer Portal
  • Products & Services
    • Back
    • View All Products
    • Infrastructure and Management
      • Back
      • Red Hat Enterprise Linux
      • Red Hat Virtualization
      • Red Hat Identity Management
      • Red Hat Directory Server
      • Red Hat Certificate System
      • Red Hat Satellite
      • Red Hat Subscription Management
      • Red Hat Update Infrastructure
      • Red Hat Insights
      • Red Hat Ansible Automation Platform
    • Cloud Computing
      • Back
      • Red Hat CloudForms
      • Red Hat OpenStack Platform
      • Red Hat OpenShift Container Platform
      • Red Hat OpenShift Online
      • Red Hat OpenShift Dedicated
      • Red Hat Advanced Cluster Management for Kubernetes
      • Red Hat Quay
      • Red Hat CodeReady Workspaces
    • Storage
      • Back
      • Red Hat Gluster Storage
      • Red Hat Hyperconverged Infrastructure
      • Red Hat Ceph Storage
      • Red Hat Openshift Container Storage
    • Runtimes
      • Back
      • Red Hat Runtimes
      • Red Hat JBoss Enterprise Application Platform
      • Red Hat Data Grid
      • Red Hat JBoss Web Server
      • Red Hat Single Sign On
      • Red Hat support for Spring Boot
      • Red Hat build of Node.js
      • Red Hat build of Thorntail
      • Red Hat build of Eclipse Vert.x
      • Red Hat build of OpenJDK
      • Red Hat build of Quarkus
      • Red Hat CodeReady Studio
    • Integration and Automation
      • Back
      • Red Hat Integration
      • Red Hat Fuse
      • Red Hat AMQ
      • Red Hat 3scale API Management
      • Red Hat JBoss Data Virtualization
      • Red Hat Process Automation
      • Red Hat Process Automation Manager
      • Red Hat Decision Manager
    • Support
    • Production Support
    • Development Support
    • Product Life Cycles
    • Documentation
    • Red Hat Enterprise Linux
    • Red Hat JBoss Enterprise Application Platform
    • Red Hat OpenStack Platform
    • Red Hat OpenShift Container Platform
    • Services
    • Consulting
    • Technical Account Management
    • Training & Certifications
    • Ecosystem Catalog
    • Partner Resources
    • Red Hat in the Public Cloud
  • Tools
    • Back
    • Red Hat Insights
    • Tools
    • Troubleshoot a product issue
    • Packages
    • Errata
    • Customer Portal Labs
    • Explore Labs
    • Configuration
    • Deployment
    • Security
    • Troubleshooting
  • Security
    • Back
    • Product Security Center
    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Security Labs
    • Resources
    • Overview
    • Security Blog
    • Security Measurement
    • Severity Ratings
    • Backporting Policies
    • Product Signing (GPG) Keys
  • Community
    • Back
    • Customer Portal Community
    • Discussions
    • Blogs
    • Private Groups
    • Community Activity
    • Customer Events
    • Red Hat Convergence
    • Red Hat Summit
    • Stories
    • Red Hat Subscription Value
    • You Asked. We Acted.
    • Open Source Communities
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Account
    • Back
    • Log In
    • Register
    • Red Hat Account Number:
    • Account Details
    • User Management
    • Account Maintenance
    • My Profile
    • Notifications
    • Help
    • Log Out
  • Language
    • Back
    • English
    • 한국어
    • 日本語
    • 中文 (中国)
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Search
  • Log In
  • Language
Or troubleshoot an issue.

Log in to Your Red Hat Account

Log In

Your Red Hat account gives you access to your profile, preferences, and services, depending on your status.

Register

If you are a new customer, register now for access to product evaluations and purchasing capabilities.

Need access to an account?

If your company has an existing Red Hat account, your organization administrator can grant you access.

If you have any questions, please contact customer service.

Red Hat Account Number:

Red Hat Account

  • Account Details
  • User Management
  • Account Maintenance
  • Account Team

Customer Portal

  • My Profile
  • Notifications
  • Help

For your security, if you’re on a public computer and have finished using your Red Hat services, please be sure to log out.

Log Out

Select Your Language

  • English
  • 한국어
  • 日本語
  • 中文 (中国)
Red Hat Customer Portal Red Hat Customer Portal
  • Products & Services
  • Tools
  • Security
  • Community
  • Infrastructure and Management

  • Cloud Computing

  • Storage

  • Runtimes

  • Integration and Automation

  • Red Hat Enterprise Linux
  • Red Hat Virtualization
  • Red Hat Identity Management
  • Red Hat Directory Server
  • Red Hat Certificate System
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Update Infrastructure
  • Red Hat Insights
  • Red Hat Ansible Automation Platform
  • Red Hat CloudForms
  • Red Hat OpenStack Platform
  • Red Hat OpenShift Container Platform
  • Red Hat OpenShift Online
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat CodeReady Workspaces
  • Red Hat OpenShift Service on AWS
  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat Openshift Container Storage
  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat Single Sign On
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Thorntail
  • Red Hat build of Eclipse Vert.x
  • Red Hat build of OpenJDK
  • Red Hat build of Quarkus
  • Red Hat CodeReady Studio
  • Red Hat Integration
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
  • Red Hat JBoss Data Virtualization
  • Red Hat Process Automation
  • Red Hat Process Automation Manager
  • Red Hat Decision Manager
View All Products
  • Support
  • Production Support
  • Development Support
  • Product Life Cycles

Services

  • Consulting
  • Technical Account Management
  • Training & Certifications
  • Documentation
  • Red Hat Enterprise Linux
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat OpenStack Platform
  • Red Hat OpenShift Container Platform
  • Ecosystem Catalog
  • Red Hat in the Public Cloud
  • Partner Resources

Tools

  • Troubleshoot a product issue
  • Packages
  • Errata
  • Customer Portal Labs
  • Configuration
  • Deployment
  • Security
  • Troubleshooting

Red Hat Insights

Increase visibility into IT operations to detect and resolve technical issues before they impact your business.

  • Learn more
  • Go to Insights

Red Hat Product Security Center

Engage with our Red Hat Product Security team, access security updates, and ensure your environments are not exposed to any known security vulnerabilities.

Product Security Center

Security Updates

  • Security Advisories
  • Red Hat CVE Database
  • Security Labs

Keep your systems secure with Red Hat's specialized responses to security vulnerabilities.

  • View Responses

Resources

  • Overview
  • Security Blog
  • Security Measurement
  • Severity Ratings
  • Backporting Policies
  • Product Signing (GPG) Keys

Customer Portal Community

  • Discussions
  • Blogs
  • Private Groups
  • Community Activity

Customer Events

  • Red Hat Convergence
  • Red Hat Summit

Stories

  • Red Hat Subscription Value
  • You Asked. We Acted.
  • Open Source Communities
Red Hat Product Errata RHSA-2021:1068 - Security Advisory
Issued:
2021-04-06
Updated:
2021-04-06

RHSA-2021:1068 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: flatpak security update

Type/Severity

Security Advisory: Important

Topic

An update for flatpak is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux.

Security Fix(es):

  • flatpak: "file forwarding" feature can be used to gain unprivileged access to files (CVE-2021-21381)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for ARM 64 8 aarch64

Fixes

  • BZ - 1936985 - CVE-2021-21381 flatpak: "file forwarding" feature can be used to gain unprivileged access to files

CVEs

  • CVE-2021-21381

References

  • https://access.redhat.com/security/updates/classification/#important
  • Note: More recent versions of these packages may be available. Click a package name for more details.

    Red Hat Enterprise Linux for x86_64 8

    SRPM
    flatpak-1.6.2-6.el8_3.src.rpm SHA-256: bf5d49427657d0c576d055b10649623c83dfee0df7fc38cfaeb803569ce4fbbd
    x86_64
    flatpak-1.6.2-6.el8_3.x86_64.rpm SHA-256: ca0022cb35e9c2542579d10e8feb921b808374433f9b04269a356dec7cb57345
    flatpak-debuginfo-1.6.2-6.el8_3.i686.rpm SHA-256: d6fe2dc4cd6dafdf1bfbdf4bd53c822ea7febce45acbaebd012e1aafcef152eb
    flatpak-debuginfo-1.6.2-6.el8_3.x86_64.rpm SHA-256: ddc7304712f9ef083c5ab766e08f2768aa11aa3388a5cbc1e87483442bf73683
    flatpak-debugsource-1.6.2-6.el8_3.i686.rpm SHA-256: 4d310bff57445c3203fa25e64b59d3d64b2fe564bf5ea7df3b901fb76f53986a
    flatpak-debugsource-1.6.2-6.el8_3.x86_64.rpm SHA-256: 55131ed5e3150c157728958dbc1fc5f5dd9ea85d18002ae26446bd0716a01c1c
    flatpak-libs-1.6.2-6.el8_3.i686.rpm SHA-256: e3ff7fa0d44aff9229d7b83c099194561fcb6eb1d9db11e9a8e9ce6116b6a1ae
    flatpak-libs-1.6.2-6.el8_3.x86_64.rpm SHA-256: 2ed5abdd43d66304aee7469b4f3687205bf4dd45e7dbfe6382f38b1c735e75f6
    flatpak-libs-debuginfo-1.6.2-6.el8_3.i686.rpm SHA-256: 7037efde76c60974ba40afdc9c36d5f7503b27731e0b1fd92d6f27acaae2d370
    flatpak-libs-debuginfo-1.6.2-6.el8_3.x86_64.rpm SHA-256: 9425a9c5deca4b94c37bfcf2d20572269a566876abdc7568a24fdc675e3820cd
    flatpak-selinux-1.6.2-6.el8_3.noarch.rpm SHA-256: 2ef34351142724814151d9f9075c3f2cea8f8ac30f85f9185559162f3fdb75ee
    flatpak-session-helper-1.6.2-6.el8_3.x86_64.rpm SHA-256: 7ceb6f76bdd3c5410eb93a9899476366ecd659cfc2269e7080b466ea7729fd90
    flatpak-session-helper-debuginfo-1.6.2-6.el8_3.i686.rpm SHA-256: b39a585c2ffaf614cc073d7bde7247e8a260973cb312e2144b63934a57088fc4
    flatpak-session-helper-debuginfo-1.6.2-6.el8_3.x86_64.rpm SHA-256: e0ce1f07680c62237ebefebcb4c7fdcd571f9a6589422c4f93f7b97d5f877aa0
    flatpak-tests-debuginfo-1.6.2-6.el8_3.i686.rpm SHA-256: 69926027bea06449af47829fcbd77e38fe4ff9fe87d1d2387a515c3ab1b48a25
    flatpak-tests-debuginfo-1.6.2-6.el8_3.x86_64.rpm SHA-256: 56fb3ab32736f7d8beb0b80e2019bd816d288893af22791d433bce4591406b23

    Red Hat Enterprise Linux for IBM z Systems 8

    SRPM
    flatpak-1.6.2-6.el8_3.src.rpm SHA-256: bf5d49427657d0c576d055b10649623c83dfee0df7fc38cfaeb803569ce4fbbd
    s390x
    flatpak-1.6.2-6.el8_3.s390x.rpm SHA-256: 11d652ffe77d037e90c673f89787b268d69f3360f2151aebe012594ee6c6a0e4
    flatpak-debuginfo-1.6.2-6.el8_3.s390x.rpm SHA-256: a247179f2c561fc5433cc558354a9b1c200c4539d2e248fa02bbc04679af5a5e
    flatpak-debugsource-1.6.2-6.el8_3.s390x.rpm SHA-256: 9c29f9abc9251084af86a58595ed811c8d6e261ce9785115a8af8df4ae7e85a1
    flatpak-libs-1.6.2-6.el8_3.s390x.rpm SHA-256: 094ce57fcd8b8c6f461a85060223ad78a9542d4a6be0183fbbc1c85d01786dd6
    flatpak-libs-debuginfo-1.6.2-6.el8_3.s390x.rpm SHA-256: a89eb681c9be691db3a882de8ff56709eebd5de53b43afcfa00b0782055e6d4d
    flatpak-selinux-1.6.2-6.el8_3.noarch.rpm SHA-256: 2ef34351142724814151d9f9075c3f2cea8f8ac30f85f9185559162f3fdb75ee
    flatpak-session-helper-1.6.2-6.el8_3.s390x.rpm SHA-256: 5c12c1f6c3b24372dde409d9440a20e875d1838976e28133365bb4b9ff647161
    flatpak-session-helper-debuginfo-1.6.2-6.el8_3.s390x.rpm SHA-256: 3fef8d64995eb5a2a7857d27e081c27064bc0b348a6e624d449ff75428f742df
    flatpak-tests-debuginfo-1.6.2-6.el8_3.s390x.rpm SHA-256: d408194695cb6528268be80bb6c16e479246487d5c7944eee17c5fa5c69db32e

    Red Hat Enterprise Linux for Power, little endian 8

    SRPM
    flatpak-1.6.2-6.el8_3.src.rpm SHA-256: bf5d49427657d0c576d055b10649623c83dfee0df7fc38cfaeb803569ce4fbbd
    ppc64le
    flatpak-1.6.2-6.el8_3.ppc64le.rpm SHA-256: c2af2cabbf72f4353de6b58dec12b81461bab800e9edb1118902001f53b09a03
    flatpak-debuginfo-1.6.2-6.el8_3.ppc64le.rpm SHA-256: 3181979c8f0758e6a08e0033b80dfa578dc5c803dcae9361a0d99b563f4d52c7
    flatpak-debugsource-1.6.2-6.el8_3.ppc64le.rpm SHA-256: 3a5e5238a9162fa856ad0bd185b5fd7830eb284b13cb24df706229a80444c0b0
    flatpak-libs-1.6.2-6.el8_3.ppc64le.rpm SHA-256: 094882001641e9ebf894c153bc015b8e8389fa431f9da8654fbc1fcba2644a16
    flatpak-libs-debuginfo-1.6.2-6.el8_3.ppc64le.rpm SHA-256: 688aa9d4cb5f325f936c768ff02f52d5c209230a00602f7ad71d5062f594da49
    flatpak-selinux-1.6.2-6.el8_3.noarch.rpm SHA-256: 2ef34351142724814151d9f9075c3f2cea8f8ac30f85f9185559162f3fdb75ee
    flatpak-session-helper-1.6.2-6.el8_3.ppc64le.rpm SHA-256: bb5f8216c9aece2b432ae79a92f89725b46b2dcce8562d0f4264e0fa3cdddc47
    flatpak-session-helper-debuginfo-1.6.2-6.el8_3.ppc64le.rpm SHA-256: ae1bfa9e4f1a65d7f8d973088101235d808f54a26f13067867cadb9e00fe524a
    flatpak-tests-debuginfo-1.6.2-6.el8_3.ppc64le.rpm SHA-256: 5c1f90f4328ed6223f52928d458c307d0dcadfbaf69eb4e892dde2ed525948b3

    Red Hat Enterprise Linux for ARM 64 8

    SRPM
    flatpak-1.6.2-6.el8_3.src.rpm SHA-256: bf5d49427657d0c576d055b10649623c83dfee0df7fc38cfaeb803569ce4fbbd
    aarch64
    flatpak-1.6.2-6.el8_3.aarch64.rpm SHA-256: 7598b6e1139f74f7b37f38eae8cbcc2c7a67020e56cad2e16681b3abf44f89d8
    flatpak-debuginfo-1.6.2-6.el8_3.aarch64.rpm SHA-256: 2e1eecfbac781af69b371c6ff37b07a5521f676bd4922ace67a5ec108b725f29
    flatpak-debugsource-1.6.2-6.el8_3.aarch64.rpm SHA-256: 075e04655ab386cf757abd9a84a9072af3dffc842b26469b7d2e8c06813d94ab
    flatpak-libs-1.6.2-6.el8_3.aarch64.rpm SHA-256: 9b9f8342035677dbb104e0727dd08796c78cf40ac15ef8623facfe744453579e
    flatpak-libs-debuginfo-1.6.2-6.el8_3.aarch64.rpm SHA-256: ee00cfc7a4b1f945617edb1331291fda1c0a0c18b8221f5e4bec5d9cc1ac5cde
    flatpak-selinux-1.6.2-6.el8_3.noarch.rpm SHA-256: 2ef34351142724814151d9f9075c3f2cea8f8ac30f85f9185559162f3fdb75ee
    flatpak-session-helper-1.6.2-6.el8_3.aarch64.rpm SHA-256: cdca385bd1d7a46d64251ad5715aee867403f75e897282f1eb1e5f738f245f2a
    flatpak-session-helper-debuginfo-1.6.2-6.el8_3.aarch64.rpm SHA-256: 9f50e6a55c48a53483d1098f6a470bcb4410399cdddc93aa2d5e7194224349bc
    flatpak-tests-debuginfo-1.6.2-6.el8_3.aarch64.rpm SHA-256: 14f52d86ca529c66388256c753d11d956945d8fcc58041e146b17c5670c88126

    The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

    Red Hat

    Quick Links

    • Downloads
    • Subscriptions
    • Support Cases
    • Customer Service
    • Product Documentation

    Help

    • Contact Us
    • Customer Portal FAQ
    • Log-in Assistance

    Site Info

    • Trust Red Hat
    • Browser Support Policy
    • Accessibility
    • Awards and Recognition
    • Colophon

    Related Sites

    • redhat.com
    • openshift.com
    • developers.redhat.com
    • connect.redhat.com
    • cloud.redhat.com

    About

    • Red Hat Subscription Value
    • About Red Hat
    • Red Hat Jobs
    Copyright © 2021 Red Hat, Inc.
    • Privacy Statement
    • Customer Portal Terms of Use
    • All Policies and Guidelines
    Red Hat Summit
    Twitter Facebook