I see that an Ubuntu developer has attempted to backport fixes for CVE-2026-87766 to the much older versions of bubblewrap that were designed to (sometimes) be setuid root, and therefore had internal privilege separation.
Previously, I wrote: > We [bubblewrap upstream] briefly investigated whether the fixes could be backported to versions older than 0.12.0, and came to the conclusion that it was not feasible and it looks as though this was accurate: the bubblewrap updates in Ubuntu have caused regressions (LP: #2167621, LP: #2167635). I suspect that the backported patches are also subject to time-of- check/time-of-use vulnerabilities, although I haven't verified this. I would encourage the Ubuntu security team to make an exception to the usual policy of backporting isolated fixes, and do an update to 0.12.0 for this particular vulnerability, as has been done in Debian and Fedora. The bubblewrap and Flatpak upstream developers are not going to provide support for these backported patches. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2166359 Title: [CVE-2026-87766, GHSA-pxhw-h44j-8pfx] Sandbox escape via symlink traversal To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/bubblewrap/+bug/2166359/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
