*** This bug is a security vulnerability *** Public security bug reported:
bubblewrap 0.12.0 fixes a security vulnerability involving symlink traversal during container setup: <https://github.com/containers/bubblewrap/security/advisories/GHSA-pxhw-h44j-8pfx>. A CVE ID has been requested but is not yet available; please refer to this vulnerability as GHSA-pxhw-h44j-8pfx until a CVE ID is allocated. All versions older than 0.12.0 are vulnerable. References: * https://github.com/containers/bubblewrap/security/advisories/GHSA-pxhw-h44j-8pfx * https://www.openwall.com/lists/oss-security/2026/08/27/7 * https://lists.debian.org/debian-security-announce/2026/msg00383.html We briefly investigated whether the fixes could be backported to versions older than 0.12.0, and came to the conclusion that it was not feasible. As a result, the Debian security team has taken bubblewrap 0.12.0 as a security update for Debian 13. Other major distros' security teams such as Fedora and Mageia seem to be doing the same. The Debian 13 version's packaging is https://salsa.debian.org/debian/bubblewrap/-/tree/debian/trixie and unofficial backports for Ubuntu LTS are available in https://github.com/flatpak/ppa-bubblewrap and https://launchpad.net/~flatpak/+archive/ubuntu/stable. If the Ubuntu security team takes bubblewrap 0.12.0 as an update like Debian did, I would appreciate it if it could be versioned as 0.12.0-1~ubuntuX instead of 0.12.0-0ubuntuX, so that it supersedes the version in the Flatpak PPA, allowing the package in the Flatpak PPA to be removed. It might be desirable to revert some of the packaging changes for older LTS branches, as seen in <https://salsa.debian.org/debian/bubblewrap/-/commits/debian/trixie>. ** Affects: bubblewrap (Ubuntu) Importance: Undecided Status: New ** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2166359 Title: [GHSA-pxhw-h44j-8pfx] Sandbox escape via symlink traversal To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/bubblewrap/+bug/2166359/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
