-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 26 Aug 2026 12:04:21 +0100 Source: bubblewrap Binary: bubblewrap bubblewrap-dbgsym Architecture: arm64 Version: 0.12.0-1~deb13u1 Distribution: trixie-security Urgency: high Maintainer: arm64 Build Daemon (arm-ubc-01) Changed-By: Simon McVittie Description: bubblewrap - utility for unprivileged chroot and namespace manipulation Closes: 1145655 Changes: bubblewrap (0.12.0-1~deb13u1) trixie-security; urgency=high . * Merge new upstream release from unstable - Prevent sandbox escape via symlink traversal. If an app framework such as Flatpak mounts subdirectories into a directory controlled by the sandboxed app, a malicious or compromised sandboxed app could create symlinks in that directory to arrange for files/directories to be created on the host system. (GHSA-pxhw-h44j-8pfx, no known CVE ID; Closes: #1145655) - bubblewrap no longer supports running when setuid, matching the upstream default. This ensures that vulnerabilities similar to CVE-2026-41163 can't happen in future. * Debian 13 backport changes: - d/control, d/gbp.conf: Branch for Debian 13 stable updates - Revert packaging changes that are not appropriate for a stable release * Packaging changes since 0.11.0-2+deb13u1: - d/rules: Stop passing -Dsupport_setuid=false. The option no longer exists, and the new version of bubblewrap always behaves as though its value was false. - d/rules: Don't compile fallback code paths for kernel older than 5.10. This ensures that we're using the safest available mechanisms, using the openat2() syscall rather than emulating it in user-space. As a result, this version will not work on kernels older than the one found in Debian 11. - d/rules: Install NEWS.md as the upstream changelog - d/p/CVE-2026-41163/: Drop patches, no longer needed/applicable with the new upstream release - d/p/debian/Change-EPERM-error-message-to-show-Debian-specific-inform.patch: Adjust patch to apply to the new upstream release - d/README.Debian: Rewrite to reflect that setuid is no longer supported - d/copyright: Update license from LGPL-2+ to LGPL-2.1+, matching upstream Checksums-Sha1: c8f3b301f9d7b48530a9e0215ed92d18dc4d9c9c 90212 bubblewrap-dbgsym_0.12.0-1~deb13u1_arm64.deb 17fc8e33cf05ae380805bbf041ecd5631a7f2604 7975 bubblewrap_0.12.0-1~deb13u1_arm64-buildd.buildinfo 04994f654e04e8920df7b2ca5cd1026696aeccbe 54820 bubblewrap_0.12.0-1~deb13u1_arm64.deb Checksums-Sha256: 7426fa454a2c86e9d5b22a2aa22fe76c92e182b112af0caf7075d7576ec37300 90212 bubblewrap-dbgsym_0.12.0-1~deb13u1_arm64.deb 8ffad57443113d78474849f9b808a9481190f29983d7ad5d036d0d78817a09d6 7975 bubblewrap_0.12.0-1~deb13u1_arm64-buildd.buildinfo d1ac1d0d81c815fc15842b9f04fdf414830ed14a0a602bf6344740f90bb36c00 54820 bubblewrap_0.12.0-1~deb13u1_arm64.deb Files: 8441705762c7247478b29361536f931c 90212 debug optional bubblewrap-dbgsym_0.12.0-1~deb13u1_arm64.deb fb3cb188b5cc262c4e0eb1a4ff0919b5 7975 admin optional bubblewrap_0.12.0-1~deb13u1_arm64-buildd.buildinfo 2d22a3cd1038733120888f523823359b 54820 admin optional bubblewrap_0.12.0-1~deb13u1_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE0Ha//LlsGOpbQ/H4xqCFmsOWgoYFAmqPLn4ACgkQxqCFmsOW goZgmw/7BiNlBL4poZEnr9W5dcyfGQDeTBUr4qzPVKIMj9NHMFmVwz+xU6AjUaMQ pVRe2YMGi6VOOOA+Pp8nvAboZasHUFOBbbyMQ9ieHvV6TbjLZs9ca5dbpbYyjvFq hU7gaJbqPSiYKooX7sFem9GC3tMaqjtYNsiIpKD9laluX6+GaCaHDLU6nIYbKc+b ZNSXr1yFbt4Qaj3kfohKyZnhpJWXdeC6GK9y7YIQ1l6hATrpvzEqofD+ccr/bhNp ujKREKwQPjWjHJzCO/Z8oNhbOlwWRDrfMrpmL7mtRhSfhet7RTS8H9mGmUiC3KCr mhQHH+KFa/F/yhI/7Feb3Mv8XdKqmGh3BnrTqUETKg/omAnXa19werkcCg47qhWb v8ehG07diN1gCqq2ERkAGcwhmITZP4aIBvMgvAJ6sa8jJ69M/HY5jb++M+j1RkEN bKJPDk7p+/KZ8ZriF4uBnMIlg6kjHU4JNYk+pbco4IcsrVhxBZ/KD33JnmQs9g8u NUO9xSsRpT8MEjoclhNEX/MEtIBHF0EV9CqgxYb4qYb0CvyRPx/IGx5DK1Vm+R7G Ciz1OeZgAnrUN94aNg7a/yAaXp4HiqN+IgNz1A7PVx7w4WDJgoYXRJr/XfWtTIqM YP2/fI6HKuFxiIU+iqRFgoMQt3EQ/SCEjokQWg5KvtuffZyxyp4= =R4FM -----END PGP SIGNATURE-----