-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 26 Aug 2026 12:04:21 +0100 Source: bubblewrap Binary: bubblewrap bubblewrap-dbgsym Architecture: armel Version: 0.12.0-1~deb13u1 Distribution: trixie-security Urgency: high Maintainer: armel Build Daemon (arm-ubc-03) Changed-By: Simon McVittie Description: bubblewrap - utility for unprivileged chroot and namespace manipulation Closes: 1145655 Changes: bubblewrap (0.12.0-1~deb13u1) trixie-security; urgency=high . * Merge new upstream release from unstable - Prevent sandbox escape via symlink traversal. If an app framework such as Flatpak mounts subdirectories into a directory controlled by the sandboxed app, a malicious or compromised sandboxed app could create symlinks in that directory to arrange for files/directories to be created on the host system. (GHSA-pxhw-h44j-8pfx, no known CVE ID; Closes: #1145655) - bubblewrap no longer supports running when setuid, matching the upstream default. This ensures that vulnerabilities similar to CVE-2026-41163 can't happen in future. * Debian 13 backport changes: - d/control, d/gbp.conf: Branch for Debian 13 stable updates - Revert packaging changes that are not appropriate for a stable release * Packaging changes since 0.11.0-2+deb13u1: - d/rules: Stop passing -Dsupport_setuid=false. The option no longer exists, and the new version of bubblewrap always behaves as though its value was false. - d/rules: Don't compile fallback code paths for kernel older than 5.10. This ensures that we're using the safest available mechanisms, using the openat2() syscall rather than emulating it in user-space. As a result, this version will not work on kernels older than the one found in Debian 11. - d/rules: Install NEWS.md as the upstream changelog - d/p/CVE-2026-41163/: Drop patches, no longer needed/applicable with the new upstream release - d/p/debian/Change-EPERM-error-message-to-show-Debian-specific-inform.patch: Adjust patch to apply to the new upstream release - d/README.Debian: Rewrite to reflect that setuid is no longer supported - d/copyright: Update license from LGPL-2+ to LGPL-2.1+, matching upstream Checksums-Sha1: c7b6e8d31b8f2895a9a9800a8e701c4a85004aba 89384 bubblewrap-dbgsym_0.12.0-1~deb13u1_armel.deb 8e201856dde9a1a590e16a83f7c3990a96941197 7840 bubblewrap_0.12.0-1~deb13u1_armel-buildd.buildinfo d4373030687098d43b4777fe6d45cbb3e47db1a4 53124 bubblewrap_0.12.0-1~deb13u1_armel.deb Checksums-Sha256: 3bd9bf72db6e8f02c694b6bc8c7cb6a2383431bd43019fdee6c55c6d75f9aac3 89384 bubblewrap-dbgsym_0.12.0-1~deb13u1_armel.deb df8515709f0b5d2847e7e6ea02ffb3c70e2d8982a61941649f579a330097f2a2 7840 bubblewrap_0.12.0-1~deb13u1_armel-buildd.buildinfo ec1d6bf8aaa8f314615075f1e3cfe6bcf05829f9b9f3d5fe1991fee736fba50d 53124 bubblewrap_0.12.0-1~deb13u1_armel.deb Files: 4eb48feec86bcf2e645daaf9041bbdca 89384 debug optional bubblewrap-dbgsym_0.12.0-1~deb13u1_armel.deb 042155becbfbc4c6e219567d409dc29e 7840 admin optional bubblewrap_0.12.0-1~deb13u1_armel-buildd.buildinfo 6a39490c8b2cfdd51ae8aa034a420ec5 53124 admin optional bubblewrap_0.12.0-1~deb13u1_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE2kd8oHy+LXk/nybqvzDqKQSGl8UFAmqPLoYACgkQvzDqKQSG l8X2LA/+Mjr6dV/Wrjqm9E0Y86R9tAiDurLZXmuwqH71+zLjCi/UhI+EdLUdO5ak fiqisRlPv9CCX20JMo7GOtmG4olwrjLkBLzAcX6NtIVip15FE0n2YCLzZEhSYNzx /3TTRq5kN8FC+oJzxy0+jYXA/M0zXBw+hVMlesQx/Ya2pawnK1Kj8lJfz+z+2gai 7rHyylJQ6EWxVAVpdUUlTrOTc3xiB9wQEQgnFC2QShnYpIUvF/z2YtnLz/trcKKj jxhmohgoDwpaQJMIU1hJ7CRkk3ZNeM0QCkeSUKU+hH3CopJGRg93DIV8dUIUKViL Dx/5sB89Ncs3zoxk4APob/d7uneaj8lgcH7wrc9mHXR6Zc+6sLYlaz1mbiatopo0 MCUOFPsAk0aY21ilaaLhApju+oY5q02ZWdpx4AZyfaIimHzsC1OEzX9B7y81tCTR woW2TtSQDjeYz+c79/CZdO6rZwahslFFnHjvbYi0wn9d1NLKVc1e9MepYztpKMUg EtZOeDT5n+7JbwfZN8vl58g6FameNsYKb+mifHO+J8C0J8+ePE7WwN7wxODov4mX 61U2WOV2HIsnc5PEvLtL4sXivmFT0UrSdPXn+yRBj9uT0J8afIot4iJaaiwacQ4u S44Y2vxd0D9aFUqZFglzLeImavwXR6HhsOZ8blEt02CsOtJNt8Q= =nJkw -----END PGP SIGNATURE-----