** Description changed:

  bubblewrap 0.12.0 fixes a security vulnerability involving symlink traversal 
during container setup:
- 
<https://github.com/containers/bubblewrap/security/advisories/GHSA-pxhw-h44j-8pfx>.
 A CVE ID has been requested but is not yet available; please refer to this 
vulnerability as GHSA-pxhw-h44j-8pfx until a CVE ID is allocated.
+ 
<https://github.com/containers/bubblewrap/security/advisories/GHSA-pxhw-h44j-8pfx>.
 Initially a CVE ID was not available, but CVE-2026-87766 has now been assigned.
  
  All versions older than 0.12.0 are vulnerable.
  
  References:
  
  * 
https://github.com/containers/bubblewrap/security/advisories/GHSA-pxhw-h44j-8pfx
  * https://www.openwall.com/lists/oss-security/2026/08/27/7
  * https://lists.debian.org/debian-security-announce/2026/msg00383.html
  
  We briefly investigated whether the fixes could be backported to
  versions older than 0.12.0, and came to the conclusion that it was not
  feasible. As a result, the Debian security team has taken bubblewrap
  0.12.0 as a security update for Debian 13. Other major distros' security
  teams such as Fedora and Mageia seem to be doing the same.
  
  The Debian 13 version's packaging is
  https://salsa.debian.org/debian/bubblewrap/-/tree/debian/trixie and
  unofficial backports for Ubuntu LTS are available in
  https://github.com/flatpak/ppa-bubblewrap and
  https://launchpad.net/~flatpak/+archive/ubuntu/stable.
  
  If the Ubuntu security team takes bubblewrap 0.12.0 as an update like
  Debian did, I would appreciate it if it could be versioned as
  0.12.0-1~ubuntuX instead of 0.12.0-0ubuntuX, so that it supersedes the
  version in the Flatpak PPA, allowing the package in the Flatpak PPA to
  be removed. It might be desirable to revert some of the packaging
  changes for older LTS branches, as seen in
  <https://salsa.debian.org/debian/bubblewrap/-/commits/debian/trixie>.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2166359

Title:
  [CVE-2026-87766, GHSA-pxhw-h44j-8pfx] Sandbox escape via symlink
  traversal

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/bubblewrap/+bug/2166359/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to