SB20260827143 - Link following in Bubblewrap



SB20260827143 - Link following in Bubblewrap

Published: August 27, 2026

Security Bulletin ID SB20260827143
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Link following (CVE-ID: N/A)

CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to write files outside the sandbox.

The vulnerability exists due to improper link resolution before file access in the bubblewrap sandbox setup logic when creating files or directories on attacker-controlled filesystem content. A local user can use symlinks that redirect through /oldroot to write files outside the sandbox.

This issue occurs during sandbox setup before anything is running inside the sandbox, and exploitation requires bubblewrap to create files on attacker-controlled filesystem content such as a malicious app image.


Remediation

Install update from vendor's website.