oss-sec mailing list archives
Re: bubblewrap 0.12.0 fixes writes outside sandbox
From: Simon McVittie <smcv () debian org>
Date: Wed, 9 Sep 2026 10:34:57 +0100
On Thu, 27 Aug 2026 at 23:04:23 +0100, Simon McVittie wrote:
bubblewrap 0.12.0 fixes a security vulnerability involving symlink traversal during container setup: <https://github.com/containers/bubblewrap/security/advisories/GHSA-pxhw-h44j-8pfx>.
CVE-2026-87766 has now been allocated for this vulnerability (thanks to Red Hat Product Security). I've updated the advisory accordingly.
smcv
Current thread:
- bubblewrap 0.12.0 fixes writes outside sandbox Simon McVittie (Aug 27)
- Re: bubblewrap 0.12.0 fixes writes outside sandbox Simon McVittie (Sep 09)
