Sandboxing breached in KDE Plasma

Well… shit happens sometimes. Nothing is perfect.

From the article linked to in op (“Arbitrary code execution breaking sandboxes in KDE Plasma”):

This proof of concept demonstrates a mean for malicious sandboxed (Flatpak here, but any sandbox apply. With or without the security context support.) applications to impersonate and, more importantly, spawn arbitrary binaries on the host when user invokes Open New Window action.

Based on the fact that KWin could not associate the window to a real .desktop file, there must be something that still allows it to find a argv0 to execute.

So it is not only restricted to Flatpaks and only restricted to KWin?

Would be nice if the title of the topic would reflect that:

Sandboxing breached in KDE Plasma

for example?

It’s only been proven with flatpaks, the other sandboxes are theoretical and should work the same so I’m going to leave that as flatpaks. I’ll adjust it to mention Plasma though.

That sounds like a supposition?

They mention clearly that “any sandbox apply”. They have only used Flatpaks as demonstration as far as I can tell by reading the article.

The title of the article says that too:

Arbitrary code execution breaking sandboxes in KDE Plasma

Flatpak is the only one proven so far, and the one most likely to be used. Also, one should read the linked blog post, just as one should read PKGBUILDs :winking_face_with_tongue:

Anyways, this is not about Flatpaks as such.

It’s about KWin :

Based on the fact that KWin could not associate the window to a real .desktop file, there must be something that still allows it to find a argv0 to execute. I took a guess on /proc/PID/cmdline and it proved to be right.

This is not limited to spawning existing application instances outside of the sandbox. Since it just so happens that any process, including unprivileged ones can change it’s argv0

So I question still the title of the topic :winking_face_with_tongue:

Aren’t we the pedant today, oh prickly one? :cactus:

The topic tile includes the only sandboxed utility tested & proven so far, as well as the DE affected. Even though I use Xfce and have no flatpaks installed, it grabbed my attention and prompted me to read the blogpost.

At least, mentioning KWin being the culprit in breaching “any sandbox”, as says the article would bring the title somewhat in line with the content of the article.

Needless to mention (but I do it anyways), before my first post pointing that out, the title of the topic read:

Flatpak sandboxing breached

That’s a far cry away from what is discussed in the article.

This is a technical forum and not a YT channel making sensational “thumbnails” to get more clicks.

Call me pedant and “pricky one” :roll_eyes:, I couldn’t care less for you being condescending .

However, what I care for, is that it is fitting for the the title of the topics posted on a technical forum, worthy of its name or pretension, to be less “sensationalist” (and that on erroneous ground) and based more on facts.

Is this a Technical forum or is it a Friendly Community that shares and exchanges Idea’s, while at the same time sharing Technical information?

Ah, I see. So the sharing of Technical information is a secondary goal, an afterthought of some sort?

Even so, shouldn’t this sharing of “Technical information” occur in such a way that it is in accordance with some facts. Out of the respect of it being “Technical” and “Information”.

That is my point, and I stand by it.

I don’t see any relevance in the “dichotomy” you are trying to create between “technical forum” and “a Friendly Community sharing Technical information”. That’s totally beside the point.

The article describes testing Flatpak on KDE Plasma, and breaching the sandbox. How on earth is that “a far cry away” :exclamation_question_mark:

It is in accordance with the facts. It’s not claiming to be about a breach of Snap sandboxing on Gnome.

And on that note, I’m going to chill out of here for a bit.

I guess if you used your own prescription:

you would, hopefully, see the it is about KWin letting “any sandboxed” application escape the sandboxing and execute arbitrary code.

It is not about Flatpak as such and its sandboxing.

Flatpaks are used as demonstration.

So to say in the title of a topic:

Flatpak sandboxing breached

which implies in a general matter of way, is not only a far cry away from what is discussed in the article. but also a totally false claim.

God! I’ve changed it back. I hope you’re happy!

It is not about my happiness. My happiness (or lack thereof) is not conditioned by the title of a topic in a technical forum or should I say in a more nuanced way,

making a sensationalist, false claim.

By the way you changed it back to the worse. Just saying :sweat_smile:

I’m only pointing out that out of all the things I’ve heard about the Forum its never been called a “Technical” Forum it was alway’s advertised as a `Family Friendly Community. Community would suggest that not everyone is TECHNICAL.

Holy moly! The comment section is a battleground…
How can a normal title lead to something like this, it’s not the end of the world

I think the issue is that people like me just read the headline and it enforces a dislike (possibly unfairly) for, in this case, Flatpak in general.

Maybe, I don’t use Flatpak. I already have an opinion on it. :rofl:

I don’t use it either for reasons but that’s not really the point. :slight_smile: