-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 26 Aug 2026 12:04:21 +0100 Source: bubblewrap Binary: bubblewrap bubblewrap-dbgsym Architecture: ppc64el Version: 0.12.0-1~deb13u1 Distribution: trixie-security Urgency: high Maintainer: ppc64el Build Daemon (ppc64el-conova-01) Changed-By: Simon McVittie Description: bubblewrap - utility for unprivileged chroot and namespace manipulation Closes: 1145655 Changes: bubblewrap (0.12.0-1~deb13u1) trixie-security; urgency=high . * Merge new upstream release from unstable - Prevent sandbox escape via symlink traversal. If an app framework such as Flatpak mounts subdirectories into a directory controlled by the sandboxed app, a malicious or compromised sandboxed app could create symlinks in that directory to arrange for files/directories to be created on the host system. (GHSA-pxhw-h44j-8pfx, no known CVE ID; Closes: #1145655) - bubblewrap no longer supports running when setuid, matching the upstream default. This ensures that vulnerabilities similar to CVE-2026-41163 can't happen in future. * Debian 13 backport changes: - d/control, d/gbp.conf: Branch for Debian 13 stable updates - Revert packaging changes that are not appropriate for a stable release * Packaging changes since 0.11.0-2+deb13u1: - d/rules: Stop passing -Dsupport_setuid=false. The option no longer exists, and the new version of bubblewrap always behaves as though its value was false. - d/rules: Don't compile fallback code paths for kernel older than 5.10. This ensures that we're using the safest available mechanisms, using the openat2() syscall rather than emulating it in user-space. As a result, this version will not work on kernels older than the one found in Debian 11. - d/rules: Install NEWS.md as the upstream changelog - d/p/CVE-2026-41163/: Drop patches, no longer needed/applicable with the new upstream release - d/p/debian/Change-EPERM-error-message-to-show-Debian-specific-inform.patch: Adjust patch to apply to the new upstream release - d/README.Debian: Rewrite to reflect that setuid is no longer supported - d/copyright: Update license from LGPL-2+ to LGPL-2.1+, matching upstream Checksums-Sha1: 5b128ebaa2061cdf9e5a186dcff52d5570173d3b 92872 bubblewrap-dbgsym_0.12.0-1~deb13u1_ppc64el.deb f379f0037fe5722e9332c5838429bad319c39c1e 7987 bubblewrap_0.12.0-1~deb13u1_ppc64el-buildd.buildinfo 0d7178c8775b07fbb44fe7a30f5dc8b4c0b6e404 58712 bubblewrap_0.12.0-1~deb13u1_ppc64el.deb Checksums-Sha256: 189db01c48a0702a44bf1275976bb79cf3eda6f74a0a2d0d0dce0d9478b683a7 92872 bubblewrap-dbgsym_0.12.0-1~deb13u1_ppc64el.deb be50ccea0c75f96114156ef4b03d7fa13f05a168a7da11321400d83739bac2d7 7987 bubblewrap_0.12.0-1~deb13u1_ppc64el-buildd.buildinfo d34fe46b9098847370b5664b00f14e8e5069018834f5f8417994e3dd69c98c8c 58712 bubblewrap_0.12.0-1~deb13u1_ppc64el.deb Files: 877a8c891d138a69f2e899640721407d 92872 debug optional bubblewrap-dbgsym_0.12.0-1~deb13u1_ppc64el.deb d7fdf8a1311444b5372f404b4e4de756 7987 admin optional bubblewrap_0.12.0-1~deb13u1_ppc64el-buildd.buildinfo 1aa2241b747a22e00df9a6003369ffbd 58712 admin optional bubblewrap_0.12.0-1~deb13u1_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEDoRc43uRWMOoIqIgDNLUPhbmg7MFAmqPLq8ACgkQDNLUPhbm g7OaKg//VREAvtOH5GHAZ/aY2sdJRGVeA0RstopZ1psJ8LogcvlZQnaji71sQlwy hN8v5AH8BRTGdVv4irT2g6xtBQiA/op7XfdexDKxnqkruAYX9Fmpn/MNGO5JlMb7 /gtJGAC2NvcAB3DKR/CriHyifn6qFTspK09DJsW21vyUVPqU4qyX1G+zE4G1OZ2J jEBoK8J4d44wCToZu89o0eZXqX36wwaiqLKsycW0wG4ADYNcPCQ0VuZ5h4KGz84d bd0/lxP7zBCKW2ioXG7+kCmqzqucwykJ50LXFdNkDaaGqUzgc+TUSpCwnzINsZY+ u4IDM+ccMzsE8OZ5tSFaZNkludImPfO89uSJonlAS9DiUuqi4KdzVWMiCHdJQas7 FApEa+kDX34zHTFPb0DQsWHwSqgiPyLEDLH7wK9vX1TsegEnKAYJQHUZTHihaLny XTanoXS7uy2cB77UvVrKvvhrtLIRiQtPgA12ZZakZ4OTY/YUDqBQIRLLwdAJ4esv 7HoWZBqPV+pwufhixCQReh/BOdFml8mxFU2N7TULNQ78cmF5Glz301P4awfelXLy tijda61WDB0SZJsqKgsVnlubMuoVJhAXJwqZAaHnxQpaWn0DKs/XapTBaXFY/D5z znKtVom/VKAudpGF2FBto4b9vEln1Qg4rWQ4CerghAtktTyeen0= =JPgX -----END PGP SIGNATURE-----