#1145655 bubblewrap: GHSA-pxhw-h44j-8pfx: sandbox escape via symlink traversal during setup

Package:
src:bubblewrap
Source:
src:bubblewrap
Submitter:
Simon McVittie
Date:
2026-09-09 09:39:02 UTC
Severity:
normal
Tags:
#1145655#5
Date:
2026-08-26 10:22:35 UTC
From:
To:
https://github.com/containers/bubblewrap/security/advisories/GHSA-pxhw-h44j-8pfx:

No CVE ID is currently available. Please reference as
GHSA-pxhw-h44j-8pfx until we have a CVE ID.

As previously discussed with the security team, fixing this in versions
older than 0.12.0 does not look feasible, so I'm going to prepare a
backport of 0.12.0 to stable.

    smcv

#1145655#10
Date:
2026-08-26 11:19:28 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
bubblewrap, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1145655@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Simon McVittie <smcv@debian.org> (supplier of updated bubblewrap package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 26 Aug 2026 11:32:16 +0100
Source: bubblewrap
Architecture: source
Version: 0.12.0-1
Distribution: unstable
Urgency: high
Maintainer: Utopia Maintenance Team <pkg-utopia-maintainers@lists.alioth.debian.org>
Changed-By: Simon McVittie <smcv@debian.org>
Closes: 1145655
Changes:
 bubblewrap (0.12.0-1) unstable; urgency=high
 .
   * New upstream release
     - Prevent sandbox escape via symlink traversal.
       If an app framework such as Flatpak mounts subdirectories into a
       directory controlled by the sandboxed app, a malicious or compromised
       sandboxed app could create symlinks in that directory to arrange for
       files/directories to be created on the host system.
       (GHSA-pxhw-h44j-8pfx, no known CVE ID; Closes: #1145655)
     - d/rules: Stop passing -Dsupport_setuid=false.
       The option no longer exists, and the new version of bubblewrap always
       behaves as though its value was false.
     - d/copyright: Update license from LGPL-2+ to LGPL-2.1+, matching upstream
     - d/p/debian/Change-EPERM-error-message-to-show-Debian-specific-inform.patch:
       Adjust patch to apply to the new upstream release
   * d/rules: Don't compile fallback code paths for kernel older than 5.10.
     This ensures that we're using the safest available mechanisms,
     using the openat2() syscall rather than emulating it in user-space.
     As a result, this version will not work on kernels older than the
     one found in Debian 11.
Checksums-Sha1:
 4ee70163fd95377cf5737e87729bc448401abacb 2427 bubblewrap_0.12.0-1.dsc
 183eaff6b078c1ea5ad55271e7d1fa5c8c0d339e 126452 bubblewrap_0.12.0.orig.tar.xz
 5a2bfd116f752cadb6c21ca2e48646bb97dcfb2c 13092 bubblewrap_0.12.0-1.debian.tar.xz
 5dfd9cab67a11e66f92a1316510eee7599591f67 7139 bubblewrap_0.12.0-1_source.buildinfo
Checksums-Sha256:
 e81987f8d90b30b581299870592affaa8d9a17caf05112d303916312b7afd60a 2427 bubblewrap_0.12.0-1.dsc
 9760d007363e3abba7c747489910f9f82d9fca53ba3bd3282e396fa3c97a3314 126452 bubblewrap_0.12.0.orig.tar.xz
 60691fa8488db2de4dd19d59fb0b084e692695c38616dcf8e20b08a4d372ab93 13092 bubblewrap_0.12.0-1.debian.tar.xz
 65322f643cfcd5b05b63231055655f62f860b2e84d4e4eb681a9d2047cb4aef6 7139 bubblewrap_0.12.0-1_source.buildinfo
Files:
 9652e93e58dd3c2c5a9a631d6f4775fe 2427 admin optional bubblewrap_0.12.0-1.dsc
 323b059c9599b60b456bcf9e9800ff44 126452 admin optional bubblewrap_0.12.0.orig.tar.xz
 255ccb24268c5460325edced14f15c9d 13092 admin optional bubblewrap_0.12.0-1.debian.tar.xz
 32130cf24c6258998317dbc4e3b634c4 7139 admin optional bubblewrap_0.12.0-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEegc60a5pT6Jb/2LlI1wJnT6zMHYFAmqOyVAACgkQI1wJnT6z
MHZl0RAAoIZj+59Kvx30Qvy7LFAJkH8YidqCQARbviv189MQ64/3F+p3tA1+p/g+
wGT/CbcrOe+Iak51pAdUHcAd3Dudd6Dta4vejkHvg3JbYON1DoigEcclYbxNdGG3
eignRxihI/E7Wlu2W3cOTNL12JGfWKTjJeTJxG2L58gxi7jXnJ2sQkANtu7t1WRh
dcq4tJvX2rwiSMMzr9cYWlCm5MFYJ7E0jkCEuHVvtMcgisjf2bahlgADcSyazPKJ
nSkW2JyvfIKuyB4kgsjT1YVwhSzKlp06fhsoDBxmtnRB2ZnGq8V0srA7K/Zo97zw
+MCh7cMus7jXwjgK/PJ3pZbwYnjGpfiMc7Lpaljiue64UXnfRNlSqDdBfjC9lQfU
JQWs5phmLoP/DrAxguKNa6m+YSPvK4BTpHjHnu8hHKftIorB3207TXjiZyLSx0wR
DBvI2W2YYoV8ibk4bC32G6Nvcs9+GcC5oTEVJFw/RlYqUugOFD3d8HlFQVVSSRbu
mhkp8VvKOJAwaRHoB4asdRIvtZ0WzQ3hrj2y4ps1iiH1UyTNmatD/XhWRJuDWv7k
Ar4DDsUa3osAuwfYX7/8mBi24YO6oWOk0gLZOtAWQtfupkVTIV0Zgl2st6fjZ2Mo
S7qn2j1YMwtjUncogR1WavqH8pa2eNr5pCJ+q/q1cty8yxA8Svo=
=fE3x
-----END PGP SIGNATURE-----

#1145655#15
Date:
2026-08-26 12:06:01 UTC
From:
To:
<https://people.debian.org/~smcv/temp/2026/bubblewrap-bug1145655/>
(debdiffs included, bubblewrap_0.12.0-1~deb13u1_debianonly.diff is
filtered to debian/ only)

A functionally equivalent test-build (differing only in the changelog)
is in
<https://people.debian.org/~smcv/temp/2026/bubblewrap-bug1145655/rc/>.

For the upstream changes, the easiest thing to review is likely to be:

git log -p --reverse --stat --ignore-space-change v0.11.0..v0.12.0

Some notes:

* commit ea185f6fb135782cabab342e33432e8482a2f5c9 "Inline the privileged
   ops" is rather noisy, unfortunately, but we've been using a version with
   that commit for a while in the Steam Runtime with no regressions
   reported.

* In commit 67d4be103b18706b5b4e3f495daa35e89e47b163 "Import safe_openat()
   from crun", as a result of -Dassume_kernel=5.10.0 we don't ever call
   chroot_realpath(), and looking for "%s%s%s" in strings(1) output confirms
   that it doesn't even get linked. This is good, because the
   implementation of chroot_realpath() scares me (far too much strcat()).
   We can confirm this with:

   $ bwrap --dev-bind / / true
   (exit 0, no output)
   $ bwrap --debug-opt=force-openat-fallback --dev-bind / / true
   bwrap: Can't open source /: Function not implemented

   (--debug-opt=force-openat-fallback emulates a pre-5.6 kernel where
   openat2() failed.)

If the security team is happy with this, there is a signed .changes in
<https://people.debian.org/~smcv/temp/2026/bubblewrap-bug1145655/bubblewrap_0.12.0-1~deb13u1_source.tar.gz.gpg>
(encrypted to the security team's key) which should be suitable for
upload to security-master, to save a round-trip from security team
approval to me uploading; or I can upload it myself if the team would
prefer that. I have also pushed the changes to
<https://salsa.debian.org/debian/bubblewrap/-/tree/debian/trixie-proposed?ref_type=heads>
and will copy that to the debian/trixie branch if accepted.

Thanks,
     smcv

#1145655#22
Date:
2026-08-26 18:00:18 UTC
From:
To:
Looks good, I've uploaded your build to security-master.

The DSA will be released tomorrow.

Cheers,
        Moritz

#1145655#27
Date:
2026-08-31 13:47:05 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
bubblewrap, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1145655@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Simon McVittie <smcv@debian.org> (supplier of updated bubblewrap package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 26 Aug 2026 12:04:21 +0100
Source: bubblewrap
Architecture: source
Version: 0.12.0-1~deb13u1
Distribution: trixie-security
Urgency: high
Maintainer: Utopia Maintenance Team <pkg-utopia-maintainers@lists.alioth.debian.org>
Changed-By: Simon McVittie <smcv@debian.org>
Closes: 1145655
Changes:
 bubblewrap (0.12.0-1~deb13u1) trixie-security; urgency=high
 .
   * Merge new upstream release from unstable
     - Prevent sandbox escape via symlink traversal.
       If an app framework such as Flatpak mounts subdirectories into a
       directory controlled by the sandboxed app, a malicious or compromised
       sandboxed app could create symlinks in that directory to arrange for
       files/directories to be created on the host system.
       (GHSA-pxhw-h44j-8pfx, no known CVE ID; Closes: #1145655)
     - bubblewrap no longer supports running when setuid, matching the
       upstream default. This ensures that vulnerabilities similar to
       CVE-2026-41163 can't happen in future.
   * Debian 13 backport changes:
     - d/control, d/gbp.conf: Branch for Debian 13 stable updates
     - Revert packaging changes that are not appropriate for a stable release
   * Packaging changes since 0.11.0-2+deb13u1:
     - d/rules: Stop passing -Dsupport_setuid=false.
       The option no longer exists, and the new version of bubblewrap always
       behaves as though its value was false.
     - d/rules: Don't compile fallback code paths for kernel older than 5.10.
       This ensures that we're using the safest available mechanisms,
       using the openat2() syscall rather than emulating it in user-space.
       As a result, this version will not work on kernels older than the
       one found in Debian 11.
     - d/rules: Install NEWS.md as the upstream changelog
     - d/p/CVE-2026-41163/:
       Drop patches, no longer needed/applicable with the new upstream release
     - d/p/debian/Change-EPERM-error-message-to-show-Debian-specific-inform.patch:
       Adjust patch to apply to the new upstream release
     - d/README.Debian: Rewrite to reflect that setuid is no longer supported
     - d/copyright: Update license from LGPL-2+ to LGPL-2.1+, matching upstream
 .
 bubblewrap (0.12.0-1) unstable; urgency=high
 .
   * New upstream release
     - Prevent sandbox escape via symlink traversal.
       If an app framework such as Flatpak mounts subdirectories into a
       directory controlled by the sandboxed app, a malicious or compromised
       sandboxed app could create symlinks in that directory to arrange for
       files/directories to be created on the host system.
       (GHSA-pxhw-h44j-8pfx, no known CVE ID; Closes: #1145655)
     - d/rules: Stop passing -Dsupport_setuid=false.
       The option no longer exists, and the new version of bubblewrap always
       behaves as though its value was false.
     - d/copyright: Update license from LGPL-2+ to LGPL-2.1+, matching upstream
     - d/p/debian/Change-EPERM-error-message-to-show-Debian-specific-inform.patch:
       Adjust patch to apply to the new upstream release
   * d/rules: Don't compile fallback code paths for kernel older than 5.10.
     This ensures that we're using the safest available mechanisms,
     using the openat2() syscall rather than emulating it in user-space.
     As a result, this version will not work on kernels older than the
     one found in Debian 11.
 .
 bubblewrap (0.11.2-2) unstable; urgency=medium
 .
   * d/rules: Stop allowing bubblewrap to run when setuid, matching
     the upstream default. This ensures that vulnerabilities similar to
     CVE-2026-41163 can't happen in future.
   * d/control, d/NEWS, d/README.Debian: Update documentation accordingly
   * Standards-Version: 4.7.4 (no changes required)
Checksums-Sha1:
 5518fac2bbaa07b5ad6bf907ab868427a1aaf308 2362 bubblewrap_0.12.0-1~deb13u1.dsc
 183eaff6b078c1ea5ad55271e7d1fa5c8c0d339e 126452 bubblewrap_0.12.0.orig.tar.xz
 87adaf7ecab19c7df09837dfeb347955405975d5 13728 bubblewrap_0.12.0-1~deb13u1.debian.tar.xz
 9e0e7b7df67852aa5f0be41bbe4a061b30fa5967 7637 bubblewrap_0.12.0-1~deb13u1_source.buildinfo
Checksums-Sha256:
 1abef77e6c35ce6c48c8969d31bffcc7a589bfd8e8fea9284fd8d77750f01d39 2362 bubblewrap_0.12.0-1~deb13u1.dsc
 9760d007363e3abba7c747489910f9f82d9fca53ba3bd3282e396fa3c97a3314 126452 bubblewrap_0.12.0.orig.tar.xz
 7b54f121aebf5d4b38360ea728274c26fa471582bc3e6658379b679ecd8b5a2f 13728 bubblewrap_0.12.0-1~deb13u1.debian.tar.xz
 6d706aa8b531e8f0745e3cbc6fb0ecb26c8900bdb3813b31b69ccedb0fde72c0 7637 bubblewrap_0.12.0-1~deb13u1_source.buildinfo
Files:
 66e88b791517fe7ae3dfcb496c7ec5f9 2362 admin optional bubblewrap_0.12.0-1~deb13u1.dsc
 323b059c9599b60b456bcf9e9800ff44 126452 admin optional bubblewrap_0.12.0.orig.tar.xz
 d804b9f84c9ed92fe0d912b40d61eb84 13728 admin optional bubblewrap_0.12.0-1~deb13u1.debian.tar.xz
 a9d0fd1cc18535a41cbd0032fa25eb54 7637 admin optional bubblewrap_0.12.0-1~deb13u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmqPKX8ACgkQEMKTtsN8
TjaD7Q//bOPiMak9bDOKeQEFXP4vhJ79AnyXrhr79FFHth6vIYXx570UVozkkku7
gzQe7I8kgrVwp0wmXvG/ySyguyZ5MV1BuovoCvDzsLDcJBrKMlZ/nUGIrWRJJYBa
km2d0y2/kgNTcA1oZyr2CpRiU14xFmrRiJHfStKln3XoDy2cy7RYTSltIScUopz1
rsEHvYX7Lqp8slW684q2rsW9ueSYeVwNyu8axlSgzcpwmG+92RyrAEVdXq7/z+xS
KBZqND+itbDLhrbHsq1yJU/wxDYgRiYP02mAHrHsXn0w91P9zLUhGxRMUHLIto8j
n5mPMheDFBZUgKfNwK4VHyPiYzZoE9B3jh9mJshABtWCRBpYnQCqHZ7qkM72z/Su
kRYFIXReZbSSrFG5CtknvUhwkwgysVOWC1CUyIitr3R7ASsvzO7UlgM5JuCB3U7U
B+0LnrHJ+opvmdxMMTqxRBi4nirGANi6GxuWSoFmVnD65upiuoZbhX3RDjwnXLe3
MMmvpuRHSGMlpeCREemy0ndV4hBwEICjogfzUMI8qHL56AmqfwX/6OcsGsCfw4Wa
GRBZ37hyrkc6my9R9qOwbH0z5ZZPtdZVaQtqHnnqS09llyoXzWIPlf6hU1irZ1M0
EDUqiDdoMhRiXI38XfJdbez1wq1+xoqTmRtVa03RCUOz4UhN3HY=
=XSuk
-----END PGP SIGNATURE-----

#1145655#32
Date:
2026-09-09 09:36:43 UTC
From:
To:
Control: retitle -1 bubblewrap: CVE-2026-87766, GHSA-pxhw-h44j-8pfx: sandbox escape via symlink traversal during setup

Red Hat Product Security has now allocated CVE-2026-87766.

     smcv