Re: bubblewrap 0.12.0 fixes writes outside sandbox
Bubblewrap 0.12.0 fixes writes outside the sandbox, tracked as CVE-2026-87766.
Simon McVittie noted on oss-security that CVE-2026-87766 was assigned for a bubblewrap flaw that allowed writes outside the sandbox. Bubblewrap 0.12.0 contains the fix. The message does not report active exploitation.
- CVE-2026-87766 covers writes outside the bubblewrap sandbox.
- Bubblewrap 0.12.0 includes the fix.
- No in-the-wild exploitation is mentioned.
Vulnerabilities mentionedAll →
- CVE-2026-877668.8<1%Symlink-following sandbox escape (arbitrary file write) in bubblewrap before 0.12.0published · bubblewrap project (freedesktop.org) bubblewrap
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-87766 | Symlink-following sandbox escape (arbitrary file write) in bubblewrap before 0.12.0 CVE-2026-87766 is a symlink-following flaw (CWE-59) in bubblewrap, the Linux sandboxing tool: during sandbox setup, when bubblewrap creates files or directories under the new root, it can follow a parent symlink through /oldroot onto the host filesystem. The attack is triggered locally (CVSS AV:L/PR:L) before the sandboxed process starts, by an attacker with low privileges who can influence the sandbox setup, for example a sandboxed application being launched or a nested-bwrap scenario, so that writes land at attacker-chosen paths outside the sandbox. The attacker gains the ability to create or overwrite files and directories on the host with the privileges of the user launching the sandbox, breaking the sandbox boundary (CVSS scope-changed, S:C, with high confidentiality, integrity and availability impact; 8.8 High). Any Linux system running bubblewrap versions prior to 0.12.0 is affected, notably desktop distributions where bubblewrap is pulled in as a Flatpak dependency and other tooling that invokes bwrap for sandboxing. No exploitation is currently known: the flaw is not in CISA KEV, no public proof-of-concept is known, and the issue (GHSA-pxhw-h44j-8pfx, assigned by Red Hat) is fixed upstream in bubblewrap 0.12.0. |
Posted by Simon McVittie on Sep 22 CVE-2026-87766 was assigned. smcv
This source does not provide full text. Read it at seclists.org.