USN-8779-1: Bubblewrap vulnerabilities
Ubuntu fixed two Bubblewrap flaws, CVE-2019-12439 and CVE-2026-87766, enabling local denial of service, code execution, or sandbox-escaped file creation.
USN-8779-1 fixes CVE-2019-12439, incorrect temporary directory handling in Bubblewrap that could allow local denial of service or arbitrary code execution, affecting only Ubuntu 18.04 LTS. It also addresses CVE-2026-87766, incorrect symlink handling during sandbox setup that lets local attackers create files outside the sandbox.
30