-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 26 Aug 2026 12:04:21 +0100 Source: bubblewrap Binary: bubblewrap bubblewrap-dbgsym Architecture: i386 Version: 0.12.0-1~deb13u1 Distribution: trixie-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Simon McVittie Description: bubblewrap - utility for unprivileged chroot and namespace manipulation Closes: 1145655 Changes: bubblewrap (0.12.0-1~deb13u1) trixie-security; urgency=high . * Merge new upstream release from unstable - Prevent sandbox escape via symlink traversal. If an app framework such as Flatpak mounts subdirectories into a directory controlled by the sandboxed app, a malicious or compromised sandboxed app could create symlinks in that directory to arrange for files/directories to be created on the host system. (GHSA-pxhw-h44j-8pfx, no known CVE ID; Closes: #1145655) - bubblewrap no longer supports running when setuid, matching the upstream default. This ensures that vulnerabilities similar to CVE-2026-41163 can't happen in future. * Debian 13 backport changes: - d/control, d/gbp.conf: Branch for Debian 13 stable updates - Revert packaging changes that are not appropriate for a stable release * Packaging changes since 0.11.0-2+deb13u1: - d/rules: Stop passing -Dsupport_setuid=false. The option no longer exists, and the new version of bubblewrap always behaves as though its value was false. - d/rules: Don't compile fallback code paths for kernel older than 5.10. This ensures that we're using the safest available mechanisms, using the openat2() syscall rather than emulating it in user-space. As a result, this version will not work on kernels older than the one found in Debian 11. - d/rules: Install NEWS.md as the upstream changelog - d/p/CVE-2026-41163/: Drop patches, no longer needed/applicable with the new upstream release - d/p/debian/Change-EPERM-error-message-to-show-Debian-specific-inform.patch: Adjust patch to apply to the new upstream release - d/README.Debian: Rewrite to reflect that setuid is no longer supported - d/copyright: Update license from LGPL-2+ to LGPL-2.1+, matching upstream Checksums-Sha1: f78f90719cd60ab59e2fdd60098c0c0bb1b8acad 84160 bubblewrap-dbgsym_0.12.0-1~deb13u1_i386.deb de4ccce39f56cf7ab79df8cd234c77be4ff32a33 7889 bubblewrap_0.12.0-1~deb13u1_i386-buildd.buildinfo 5acefdb80de12447de03e4d4f243207cd52aaa82 59304 bubblewrap_0.12.0-1~deb13u1_i386.deb Checksums-Sha256: 2d26124b95b6d998048a05b353d6ca74393559b159fd57ed18b8f71c06fd2850 84160 bubblewrap-dbgsym_0.12.0-1~deb13u1_i386.deb d860fb97537cbf2338ff1a60b2be65acba669f6d0371ef83f096aaccdec2ba48 7889 bubblewrap_0.12.0-1~deb13u1_i386-buildd.buildinfo 62af23bba2e5af9974caab11fd1e670fec7610f661568c18c9990593b90da5f7 59304 bubblewrap_0.12.0-1~deb13u1_i386.deb Files: 47d5d2ebe5af7536edec3e22626908c4 84160 debug optional bubblewrap-dbgsym_0.12.0-1~deb13u1_i386.deb da86e90af7b1d038cca3644b64d2aa50 7889 admin optional bubblewrap_0.12.0-1~deb13u1_i386-buildd.buildinfo 4a6736d474dc7392d06b0a9f2aee2bec 59304 admin optional bubblewrap_0.12.0-1~deb13u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEmtr4KUMaso2EQ6NrTwt/65ON6zcFAmqPLq8ACgkQTwt/65ON 6zcddA//UnKMe3fepKNudWIUgcbmQW+acW1szSw7R0j0y9KpXK2yD/NJREGYIU9v bJS4i3QYgkPJXpSs+kE+PF3qLyk6L55r0jnL44MPlGkPCCmsRN/KlVnQsXbXZty+ FQWHYa1I4AyDyCF29nKXPK9KkunlUBeXIqfR3A9e3WEOEPaOjZw9qM1gatTa5QIw zvs46fSiNnf/6PyY9LZBN4WsVgJWGVX/J7EQgUw12zatKoH36UChiTeG2hd3j5bj meHih2BIpN3Qa27Q+iZKZWN+c1bDZv10CYQWxa9yH6EXLprWKkKKUk7lY1mJg0rl bDTGrSy0FItywvbAsGaxH0gTvvoEAP63/5h0HUR+QJQ3sNLWyz3P796ug9YcAmir adrLVYEnYlY+8iCN0AI73ELaxe9/l1O+bCWUkABqovLjm/4d6Ycm1tH+fgl+ASMJ Is8/W1dltPGMLGQR0/nivyACpW05F+0EGC/mV1ZfBe/uljnnNeU9ATPndC0TM3Jq i5UT/zUWDHEG/IZRYQxB2phehb7v/Kf40IaTTRwJcBH6SDB2SIDWzsio+5LofcvJ WGCzI0PbWP02Mxi9gsJG5KCbsXVxEt7o9jAQIA5qygw4YbBpAikNauV38X8UEx14 beoaJ5LK0N4rxlE9Z99Z8gJr3taGI9tnNuu0ApkzOeMa9JjNhcc= =4OjG -----END PGP SIGNATURE-----