Your message dated Wed, 26 Aug 2026 11:19:28 +0000
with message-id <[email protected]>
and subject line Bug#1145655: fixed in bubblewrap 0.12.0-1
has caused the Debian Bug report #1145655,
regarding bubblewrap: GHSA-pxhw-h44j-8pfx: sandbox escape via symlink traversal
during setup
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1145655: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1145655
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: bubblewrap
Version: 0.1.0
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: Debian Security Team <[email protected]>
https://github.com/containers/bubblewrap/security/advisories/GHSA-pxhw-h44j-8pfx:
>If bubblewrap is used to create files on attacker controlled filesystem
>content (such as a malicious app image), then the attacker can use
>symlinks to redirect those file to be created on the host. This happens
>during setup of the sandbox, before anything is running, so there is no
>way to escape a sandbox at runtime.
>
>The bubblewrap arguments are not typically under the attackers control,
>so the risks depend on exactly how bwrap it is being used. Any files
>created by bubblewrap in this way are created by the uid/gid that
>launched bubblewrap, which is generally not root, so sandbox escapes
>are not privileged.
>
>This vulnerability affects Flatpak if a malicious or compromised app
>is used, and potentially affects other app frameworks that work in a
>similar way.
No CVE ID is currently available. Please reference as
GHSA-pxhw-h44j-8pfx until we have a CVE ID.
As previously discussed with the security team, fixing this in versions
older than 0.12.0 does not look feasible, so I'm going to prepare a
backport of 0.12.0 to stable.
smcv
--- End Message ---
--- Begin Message ---
Source: bubblewrap
Source-Version: 0.12.0-1
Done: Simon McVittie <[email protected]>
We believe that the bug you reported is fixed in the latest version of
bubblewrap, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Simon McVittie <[email protected]> (supplier of updated bubblewrap package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Wed, 26 Aug 2026 11:32:16 +0100
Source: bubblewrap
Architecture: source
Version: 0.12.0-1
Distribution: unstable
Urgency: high
Maintainer: Utopia Maintenance Team
<[email protected]>
Changed-By: Simon McVittie <[email protected]>
Closes: 1145655
Changes:
bubblewrap (0.12.0-1) unstable; urgency=high
.
* New upstream release
- Prevent sandbox escape via symlink traversal.
If an app framework such as Flatpak mounts subdirectories into a
directory controlled by the sandboxed app, a malicious or compromised
sandboxed app could create symlinks in that directory to arrange for
files/directories to be created on the host system.
(GHSA-pxhw-h44j-8pfx, no known CVE ID; Closes: #1145655)
- d/rules: Stop passing -Dsupport_setuid=false.
The option no longer exists, and the new version of bubblewrap always
behaves as though its value was false.
- d/copyright: Update license from LGPL-2+ to LGPL-2.1+, matching upstream
-
d/p/debian/Change-EPERM-error-message-to-show-Debian-specific-inform.patch:
Adjust patch to apply to the new upstream release
* d/rules: Don't compile fallback code paths for kernel older than 5.10.
This ensures that we're using the safest available mechanisms,
using the openat2() syscall rather than emulating it in user-space.
As a result, this version will not work on kernels older than the
one found in Debian 11.
Checksums-Sha1:
4ee70163fd95377cf5737e87729bc448401abacb 2427 bubblewrap_0.12.0-1.dsc
183eaff6b078c1ea5ad55271e7d1fa5c8c0d339e 126452 bubblewrap_0.12.0.orig.tar.xz
5a2bfd116f752cadb6c21ca2e48646bb97dcfb2c 13092
bubblewrap_0.12.0-1.debian.tar.xz
5dfd9cab67a11e66f92a1316510eee7599591f67 7139
bubblewrap_0.12.0-1_source.buildinfo
Checksums-Sha256:
e81987f8d90b30b581299870592affaa8d9a17caf05112d303916312b7afd60a 2427
bubblewrap_0.12.0-1.dsc
9760d007363e3abba7c747489910f9f82d9fca53ba3bd3282e396fa3c97a3314 126452
bubblewrap_0.12.0.orig.tar.xz
60691fa8488db2de4dd19d59fb0b084e692695c38616dcf8e20b08a4d372ab93 13092
bubblewrap_0.12.0-1.debian.tar.xz
65322f643cfcd5b05b63231055655f62f860b2e84d4e4eb681a9d2047cb4aef6 7139
bubblewrap_0.12.0-1_source.buildinfo
Files:
9652e93e58dd3c2c5a9a631d6f4775fe 2427 admin optional bubblewrap_0.12.0-1.dsc
323b059c9599b60b456bcf9e9800ff44 126452 admin optional
bubblewrap_0.12.0.orig.tar.xz
255ccb24268c5460325edced14f15c9d 13092 admin optional
bubblewrap_0.12.0-1.debian.tar.xz
32130cf24c6258998317dbc4e3b634c4 7139 admin optional
bubblewrap_0.12.0-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEegc60a5pT6Jb/2LlI1wJnT6zMHYFAmqOyVAACgkQI1wJnT6z
MHZl0RAAoIZj+59Kvx30Qvy7LFAJkH8YidqCQARbviv189MQ64/3F+p3tA1+p/g+
wGT/CbcrOe+Iak51pAdUHcAd3Dudd6Dta4vejkHvg3JbYON1DoigEcclYbxNdGG3
eignRxihI/E7Wlu2W3cOTNL12JGfWKTjJeTJxG2L58gxi7jXnJ2sQkANtu7t1WRh
dcq4tJvX2rwiSMMzr9cYWlCm5MFYJ7E0jkCEuHVvtMcgisjf2bahlgADcSyazPKJ
nSkW2JyvfIKuyB4kgsjT1YVwhSzKlp06fhsoDBxmtnRB2ZnGq8V0srA7K/Zo97zw
+MCh7cMus7jXwjgK/PJ3pZbwYnjGpfiMc7Lpaljiue64UXnfRNlSqDdBfjC9lQfU
JQWs5phmLoP/DrAxguKNa6m+YSPvK4BTpHjHnu8hHKftIorB3207TXjiZyLSx0wR
DBvI2W2YYoV8ibk4bC32G6Nvcs9+GcC5oTEVJFw/RlYqUugOFD3d8HlFQVVSSRbu
mhkp8VvKOJAwaRHoB4asdRIvtZ0WzQ3hrj2y4ps1iiH1UyTNmatD/XhWRJuDWv7k
Ar4DDsUa3osAuwfYX7/8mBi24YO6oWOk0gLZOtAWQtfupkVTIV0Zgl2st6fjZ2Mo
S7qn2j1YMwtjUncogR1WavqH8pa2eNr5pCJ+q/q1cty8yxA8Svo=
=fE3x
-----END PGP SIGNATURE-----
pgpSAnUSZ_HQ_.pgp
Description: PGP signature
--- End Message ---