Opened 5 weeks ago

Closed 3 weeks ago

#23812 closed enhancement (fixed)

bubblewrap-0.12.0

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: elevated Milestone: 98-Security
Component: BOOK Version: git
Severity: high Keywords:
Cc:

Description

New minor version.

Change History (4)

comment:1 by Joe Locash, 5 weeks ago

Priority: normal → elevated
Severity: normal → high
bubblewrap 0.12.0
=================

Released: 2026-08-26

Enhancements:

 * The flag --not-a-security-boundary was added. If this is enabled
   then failure of some sandbox setup steps (like remounting a
   submount) are not fatal.

 * The license has been updated from LGPL 2.0 (or later) to LGPL 2.1
   (or later).

 * This version removes the support for building a setuid
   bubblewrap. Changes in this version made it difficult to support
   and basically all modern linux distributions now support
   unprivileged user namespaces to some extent.

 * The assume_kernel build option was added, if specified no backwards
   compatiblity for kernels older than this is built in (and will result
   in hard failures at runtime). Currently specifying 5.6.0 or
   later will disable the fallback implementation of
   openat2(RESOLVE_IN_ROOT).

Bug fixes:

  * Bubblewrap now correctly resolves absolute symlinks during the
    sandbox setup by using openat2 with RESOLVE_IN_ROOT (or a fallback
    implementation). This fixes a security issue (GHSA-pxhw-h44j-8pfx)
    where file or directories created during sandbox setup could
    follow parent symlinks out of the sandbox.

Link to the GH advisory: ​https://github.com/containers/bubblewrap/security/advisories/GHSA-pxhw-h44j-8pfx

It has a rating of 8.8/10.

comment:2 by Joe Locash, 4 weeks ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:3 by Joe Locash, 4 weeks ago

Milestone: 13.2 → 98-Security
Owner: changed from Joe Locash to SecurityAdvisory
Status: assigned → new

Fixed at 4fed78473a. Leaving open for SA.

comment:4 by Bruce Dubbs, 3 weeks ago

Resolution: → fixed
Status: new → closed

Advisory sa-13.1-006 has been issued.

Note: See TracTickets for help on using tickets.