SB20261001135 - Ubuntu update for bubblewrap



SB20261001135 - Ubuntu update for bubblewrap

Published: October 1, 2026

Security Bulletin ID SB20261001135
CSH Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

High 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Link following (CVE-ID: CVE-2026-87766)

CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to write files outside the sandbox.

The vulnerability exists due to improper link resolution before file access in the bubblewrap sandbox setup logic when creating files or directories on attacker-controlled filesystem content. A local user can use symlinks that redirect through /oldroot to write files outside the sandbox.

This issue occurs during sandbox setup before anything is running inside the sandbox, and exploitation requires bubblewrap to create files on attacker-controlled filesystem content such as a malicious app image.


2) Input validation error (CVE-ID: CVE-2019-12439)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to perform a denial of service (DoS) attack.

The vulnerability exists due due to the insecure use of the /tmp directory by the bubblewrap.c source code file of the affected software. A local attacker can execute arbitrary code or cause a (DoS) attack by preventing other users from executing bubblewrap from executing the affected application.


Remediation

Install update from vendor's website.