oss-sec mailing list archives

Re: bubblewrap 0.12.0 fixes writes outside sandbox


From: Simon McVittie <smcv () debian org>
Date: Wed, 9 Sep 2026 10:34:57 +0100

On Thu, 27 Aug 2026 at 23:04:23 +0100, Simon McVittie wrote:
bubblewrap 0.12.0 fixes a security vulnerability
involving symlink traversal during container setup:
<https://github.com/containers/bubblewrap/security/advisories/GHSA-pxhw-h44j-8pfx>.

CVE-2026-87766 has now been allocated for this vulnerability (thanks to Red Hat Product Security). I've updated the advisory accordingly.

    smcv


Current thread: