I see that an Ubuntu developer has attempted to backport fixes for
CVE-2026-87766 to the much older versions of bubblewrap that were
designed to (sometimes) be setuid root, and therefore had internal
privilege separation.

Previously, I wrote:

> We [bubblewrap upstream] briefly investigated whether the fixes could
be backported to versions older than 0.12.0, and came to the conclusion
that it was not feasible

and it looks as though this was accurate: the bubblewrap updates in
Ubuntu have caused regressions (LP: #2167621, LP: #2167635).

I suspect that the backported patches are also subject to time-of-
check/time-of-use vulnerabilities, although I haven't verified this.

I would encourage the Ubuntu security team to make an exception to the
usual policy of backporting isolated fixes, and do an update to 0.12.0
for this particular vulnerability, as has been done in Debian and
Fedora.

The bubblewrap and Flatpak upstream developers are not going to provide
support for these backported patches.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2166359

Title:
  [CVE-2026-87766, GHSA-pxhw-h44j-8pfx] Sandbox escape via symlink
  traversal

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/bubblewrap/+bug/2166359/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to