SB20261001136 - Ubuntu update for bubblewrap
Published: October 1, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Input validation error (CVE-ID: CVE-2019-12439)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to perform a denial of service (DoS) attack.
The vulnerability exists due due to the insecure use of the /tmp directory by the bubblewrap.c source code file of the affected software. A local attacker can execute arbitrary code or cause a (DoS) attack by preventing other users from executing bubblewrap from executing the affected application.
2) Link following (CVE-ID: CVE-2026-87766)
CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to write files outside the sandbox.
The vulnerability exists due to improper link resolution before file access in the bubblewrap sandbox setup logic when creating files or directories on attacker-controlled filesystem content. A local user can use symlinks that redirect through /oldroot to write files outside the sandbox.
This issue occurs during sandbox setup before anything is running inside the sandbox, and exploitation requires bubblewrap to create files on attacker-controlled filesystem content such as a malicious app image.
Remediation
Install update from vendor's website.