[ GLSA 202608-09 ] Bubblewrap: Root privilege escalation

[email protected]
Newsgroups gmane.linux.gentoo.announce
Message-ID <178667019810.1.17063209595263679062@cdebd0f5f1fc>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202608-09
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: High
    Title: Bubblewrap: Root privilege escalation
     Date: August 14, 2026
     Bugs: #973131
       ID: 202608-09

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

A vulnerability has been discovered in Bubblewrap that would allow root
privilege escalation.

Background
==========

Bubblewrap is an unprivileged sandboxing tool namespaces-powered chroot-
like solution.

Affected packages
=================

Package              Vulnerable    Unaffected
-------------------  ------------  ------------
sys-apps/bubblewrap  < 0.11.2      >= 0.11.2

Description
===========

A vulnerability has been discovered in Bubblewrap. Please review the CVE
identifier referenced below for details.

Impact
======

An attacker could achieve root privilege escalation if Bubblewrap is
used in its suid mode.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All Bubblewrap users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=sys-apps/bubblewrap-0.11.2"

References
==========

[ 1 ] CVE-2026-41163
      https://nvd.nist.gov/vuln/detail/CVE-2026-41163

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202608-09

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2026 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 870 B)
-----BEGIN PGP SIGNATURE-----

iQJPBAEBCAA5FiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmp+bHUbFIAAAAAABAAO
bWFudTIsMi41KzEuMTIsMiwyAAoJEBTEJDmlcvvZOeoQAMWisz0IVRJiJ+LXzH8z
Ea5yaQeJYsCk/rm0JzrBSzIEmegSWUJt8z6hQWQDU6ULiY6/YRzVKNaGp7QQtqXT
GFPupoORv6UptlvzRJBeHBYTfshSw7ACUsee54ffjkuIVYrqLpERqLaMpEyeb/co
OuRqSnVi+XdcxCAy2fXkXANDZ0+GHxc1WBPrcmvrjBMOS3eSeytG4SlQR1QXa2kR
NTxhlha7rqcIo+wqUqbMmUCDGir2I316onV1b0P3xT1KyMdxf8T2YDObFFCHkxr0
BYlOeov3PoKsogii1799dP9wmATsa8SMuFEe/yrt9W1J9besKFCNI5OnDj2sCD6x
Jp538bDWHickXFEXRi+CrMoomJZqTTZY1q/vwg+RqrqLdu6Vk9Bwb4khCDNBLjDF
Ey7xY6WSeqeVbTFE0NXME5/8PQJ8nKiDa3TvjPPFx1knJRw1WdrsnYvs/AK7lOBC
XqZxtvFJFidvyGlCq+ySpPonzt+xBUQdCfZyVRN3O6qaXK7ZOaThT60ivaR3fHaM
RYncDUlnpbLOUNJhwzwyurx7ejVIDVOrVr6RGDvz/RzlKQTut8qFrXwrN8AeBRSt
N5FloJ8noGb6Ep/HM3tauolh0z+T2ur8a8cIbm3EHTjo8mcQx3WlKWHOZInWPxCP
IZgKMApbjY8tgYnqEBUG3ITN
=a8c8
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.