USN-8779-2: Bubblewrap regression
Ubuntu issued USN-8779-2 reverting a Bubblewrap symlink fix for CVE-2026-87766 that caused a regression preventing some Flatpak apps from launching.
USN-8779-2 reverts the CVE-2026-87766 fix from USN-8779-1 because it introduced a regression in symlink resolution that stopped certain Flatpak applications from launching; a complete fix is still pending. The original advisory detailed CVE-2019-12439, where mishandled temporary directories could let a local attacker cause denial of service or execute arbitrary code on Ubuntu 18.04 LTS only, plus improper symlink handling during sandbox setup with similar local impact.