-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 26 Aug 2026 12:04:21 +0100 Source: bubblewrap Binary: bubblewrap bubblewrap-dbgsym Architecture: amd64 Version: 0.12.0-1~deb13u1 Distribution: trixie-security Urgency: high Maintainer: all / amd64 / i386 Build Daemon (x86-conova-01) Changed-By: Simon McVittie Description: bubblewrap - utility for unprivileged chroot and namespace manipulation Closes: 1145655 Changes: bubblewrap (0.12.0-1~deb13u1) trixie-security; urgency=high . * Merge new upstream release from unstable - Prevent sandbox escape via symlink traversal. If an app framework such as Flatpak mounts subdirectories into a directory controlled by the sandboxed app, a malicious or compromised sandboxed app could create symlinks in that directory to arrange for files/directories to be created on the host system. (GHSA-pxhw-h44j-8pfx, no known CVE ID; Closes: #1145655) - bubblewrap no longer supports running when setuid, matching the upstream default. This ensures that vulnerabilities similar to CVE-2026-41163 can't happen in future. * Debian 13 backport changes: - d/control, d/gbp.conf: Branch for Debian 13 stable updates - Revert packaging changes that are not appropriate for a stable release * Packaging changes since 0.11.0-2+deb13u1: - d/rules: Stop passing -Dsupport_setuid=false. The option no longer exists, and the new version of bubblewrap always behaves as though its value was false. - d/rules: Don't compile fallback code paths for kernel older than 5.10. This ensures that we're using the safest available mechanisms, using the openat2() syscall rather than emulating it in user-space. As a result, this version will not work on kernels older than the one found in Debian 11. - d/rules: Install NEWS.md as the upstream changelog - d/p/CVE-2026-41163/: Drop patches, no longer needed/applicable with the new upstream release - d/p/debian/Change-EPERM-error-message-to-show-Debian-specific-inform.patch: Adjust patch to apply to the new upstream release - d/README.Debian: Rewrite to reflect that setuid is no longer supported - d/copyright: Update license from LGPL-2+ to LGPL-2.1+, matching upstream Checksums-Sha1: 5a767cc843fbdac9e562f08ea469f94c20bc926a 92652 bubblewrap-dbgsym_0.12.0-1~deb13u1_amd64.deb 919a5323bc0b40de3e26893efad397fff678363c 7988 bubblewrap_0.12.0-1~deb13u1_amd64-buildd.buildinfo bc858614dea46c779fe2b1a1d40643de47dd4f9c 56876 bubblewrap_0.12.0-1~deb13u1_amd64.deb Checksums-Sha256: 3647a6f65bbcf9956ead4ad4ae1c61005804741ab5d53f47a811712cbced7d0d 92652 bubblewrap-dbgsym_0.12.0-1~deb13u1_amd64.deb 0253bcb9174aa8ad3531bf65c826b27ad45b5e2e4358cd7825df4eaae3e95a61 7988 bubblewrap_0.12.0-1~deb13u1_amd64-buildd.buildinfo 70aca4fa8daeacb677ec00e8063eb586f08ae3d94b1f11e684370b5524c43431 56876 bubblewrap_0.12.0-1~deb13u1_amd64.deb Files: 983b34b8d02b8fe53dfdad1ee46914bc 92652 debug optional bubblewrap-dbgsym_0.12.0-1~deb13u1_amd64.deb e88b8a00fcad03e90b13e2ee01b0a853 7988 admin optional bubblewrap_0.12.0-1~deb13u1_amd64-buildd.buildinfo 2fcd5837ea30c762e7c944c0e8252dac 56876 admin optional bubblewrap_0.12.0-1~deb13u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7cQ9mRD4+dWjjrb6PkCWRKsh20cFAmqPLoUACgkQPkCWRKsh 20e9MA//ZBqdj8xYcyCSLh7DbtyJTBmv6cJV93r1kmddXAyZbcB3OqP5jOXfWfkQ Q/2AdoDgXfHWzNZzz1Qq9am1K5GJNMzICngZge9KvscZpgjKK7JFoJwZ14y988kW MTsy9R8HGJEuG/vXTXlzcxQfmacddrSLZuk9A1Y0V2jDiovesFpxekJbuW3rwzoI m2ttIEPSZxM8P1LTIhOE0iqmheFdjhebiAwq6lnBdXv/jQFT6Yij0UW1KqXbapF8 xfXBOlGjNP63B8Bx/w7P9PtUUCzqSVq8hpeT2JQeTr15nP0cPj3eohwGyUXAqD77 lvw4Yg8vJPvsw1w8aWwVz8n5506LYw37xx8AhbUTvUkYtd1JyTbkDXBTSIlsBgFa w4GFX3OLnHTO2TCIbpCLaH9FupSeJ1Zw4YbSsNlhq9d3bQL3FkM7HhtRHD21ckZt 5F7OX5gn9iwMe7vozcNg6k1A95/RpqNiGVsUjnToUAfzvinb8Vc1/XfHfpdE6ZJ8 WVFdGDKm2zpeKnytao0iuZpP34C1b1Fdlw/+oVvtnmNVjHRa513Nyl+g4AfW3aJc 1lnVD8FWe93Jkf2W1/VfMO5/OdS2TQiujqF70fHOp7Nm2NujU3lpYDaL2gW6H2Lp YjKtJYTCQG3/pYFsZqp0/0drGmLv89VlvA6SPpdVgCZ6Wl5n/NE= =jLoq -----END PGP SIGNATURE-----