Opened 5 weeks ago
Closed 3 weeks ago
#23812 closed enhancement (fixed)
bubblewrap-0.12.0
| Reported by: | Bruce Dubbs | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | elevated | Milestone: | 98-Security |
| Component: | BOOK | Version: | git |
| Severity: | high | Keywords: | |
| Cc: |
Description
New minor version.
Change History (4)
comment:1 by , 5 weeks ago
| Priority: | normal → elevated |
|---|---|
| Severity: | normal → high |
comment:2 by , 4 weeks ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:3 by , 4 weeks ago
| Milestone: | 13.2 → 98-Security |
|---|---|
| Owner: | changed from to |
| Status: | assigned → new |
Fixed at 4fed78473a. Leaving open for SA.
comment:4 by , 3 weeks ago
| Resolution: | → fixed |
|---|---|
| Status: | new → closed |
Advisory sa-13.1-006 has been issued.
Note:
See TracTickets
for help on using tickets.

bubblewrap 0.12.0 ================= Released: 2026-08-26 Enhancements: * The flag --not-a-security-boundary was added. If this is enabled then failure of some sandbox setup steps (like remounting a submount) are not fatal. * The license has been updated from LGPL 2.0 (or later) to LGPL 2.1 (or later). * This version removes the support for building a setuid bubblewrap. Changes in this version made it difficult to support and basically all modern linux distributions now support unprivileged user namespaces to some extent. * The assume_kernel build option was added, if specified no backwards compatiblity for kernels older than this is built in (and will result in hard failures at runtime). Currently specifying 5.6.0 or later will disable the fallback implementation of openat2(RESOLVE_IN_ROOT). Bug fixes: * Bubblewrap now correctly resolves absolute symlinks during the sandbox setup by using openat2 with RESOLVE_IN_ROOT (or a fallback implementation). This fixes a security issue (GHSA-pxhw-h44j-8pfx) where file or directories created during sandbox setup could follow parent symlinks out of the sandbox.Link to the GH advisory: https://github.com/containers/bubblewrap/security/advisories/GHSA-pxhw-h44j-8pfx
It has a rating of 8.8/10.