*** This bug is a security vulnerability ***

Public security bug reported:

bubblewrap 0.12.0 fixes a security vulnerability involving symlink traversal 
during container setup:
<https://github.com/containers/bubblewrap/security/advisories/GHSA-pxhw-h44j-8pfx>.
 A CVE ID has been requested but is not yet available; please refer to this 
vulnerability as GHSA-pxhw-h44j-8pfx until a CVE ID is allocated.

All versions older than 0.12.0 are vulnerable.

References:

* 
https://github.com/containers/bubblewrap/security/advisories/GHSA-pxhw-h44j-8pfx
* https://www.openwall.com/lists/oss-security/2026/08/27/7
* https://lists.debian.org/debian-security-announce/2026/msg00383.html

We briefly investigated whether the fixes could be backported to
versions older than 0.12.0, and came to the conclusion that it was not
feasible. As a result, the Debian security team has taken bubblewrap
0.12.0 as a security update for Debian 13. Other major distros' security
teams such as Fedora and Mageia seem to be doing the same.

The Debian 13 version's packaging is
https://salsa.debian.org/debian/bubblewrap/-/tree/debian/trixie and
unofficial backports for Ubuntu LTS are available in
https://github.com/flatpak/ppa-bubblewrap and
https://launchpad.net/~flatpak/+archive/ubuntu/stable.

If the Ubuntu security team takes bubblewrap 0.12.0 as an update like
Debian did, I would appreciate it if it could be versioned as
0.12.0-1~ubuntuX instead of 0.12.0-0ubuntuX, so that it supersedes the
version in the Flatpak PPA, allowing the package in the Flatpak PPA to
be removed. It might be desirable to revert some of the packaging
changes for older LTS branches, as seen in
<https://salsa.debian.org/debian/bubblewrap/-/commits/debian/trixie>.

** Affects: bubblewrap (Ubuntu)
     Importance: Undecided
         Status: New

** Information type changed from Private Security to Public Security

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2166359

Title:
  [GHSA-pxhw-h44j-8pfx] Sandbox escape via symlink traversal

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/bubblewrap/+bug/2166359/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to