-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 26 Aug 2026 12:04:21 +0100 Source: bubblewrap Binary: bubblewrap bubblewrap-dbgsym Architecture: armhf Version: 0.12.0-1~deb13u1 Distribution: trixie-security Urgency: high Maintainer: armhf Build Daemon (arm-conova-04) Changed-By: Simon McVittie Description: bubblewrap - utility for unprivileged chroot and namespace manipulation Closes: 1145655 Changes: bubblewrap (0.12.0-1~deb13u1) trixie-security; urgency=high . * Merge new upstream release from unstable - Prevent sandbox escape via symlink traversal. If an app framework such as Flatpak mounts subdirectories into a directory controlled by the sandboxed app, a malicious or compromised sandboxed app could create symlinks in that directory to arrange for files/directories to be created on the host system. (GHSA-pxhw-h44j-8pfx, no known CVE ID; Closes: #1145655) - bubblewrap no longer supports running when setuid, matching the upstream default. This ensures that vulnerabilities similar to CVE-2026-41163 can't happen in future. * Debian 13 backport changes: - d/control, d/gbp.conf: Branch for Debian 13 stable updates - Revert packaging changes that are not appropriate for a stable release * Packaging changes since 0.11.0-2+deb13u1: - d/rules: Stop passing -Dsupport_setuid=false. The option no longer exists, and the new version of bubblewrap always behaves as though its value was false. - d/rules: Don't compile fallback code paths for kernel older than 5.10. This ensures that we're using the safest available mechanisms, using the openat2() syscall rather than emulating it in user-space. As a result, this version will not work on kernels older than the one found in Debian 11. - d/rules: Install NEWS.md as the upstream changelog - d/p/CVE-2026-41163/: Drop patches, no longer needed/applicable with the new upstream release - d/p/debian/Change-EPERM-error-message-to-show-Debian-specific-inform.patch: Adjust patch to apply to the new upstream release - d/README.Debian: Rewrite to reflect that setuid is no longer supported - d/copyright: Update license from LGPL-2+ to LGPL-2.1+, matching upstream Checksums-Sha1: c01db128c03ae6335ac5f220cb26b2fbac4a65ad 89956 bubblewrap-dbgsym_0.12.0-1~deb13u1_armhf.deb 6ec0e91ef19a6b4e817b8f15226db0f605fd0aad 7854 bubblewrap_0.12.0-1~deb13u1_armhf-buildd.buildinfo 54a543c4d2ce67c2a11e17eec7a9b93396afd684 53724 bubblewrap_0.12.0-1~deb13u1_armhf.deb Checksums-Sha256: 79efd235832c8b5252b1093aa01e2ab13a862290f31bf4408f34be4aea867a82 89956 bubblewrap-dbgsym_0.12.0-1~deb13u1_armhf.deb d8a3d655cba829831cb291ff89e99ded62f178c8186143215ad4f4c626eb6b64 7854 bubblewrap_0.12.0-1~deb13u1_armhf-buildd.buildinfo e0c09b03161b8251a8d00a21f3a947575a44232a633a468f0037ba3f98933021 53724 bubblewrap_0.12.0-1~deb13u1_armhf.deb Files: 1e10cfb1250ca2f9e67abf3b448a173a 89956 debug optional bubblewrap-dbgsym_0.12.0-1~deb13u1_armhf.deb 9df5c00b8a37387734b3bfa58795d906 7854 admin optional bubblewrap_0.12.0-1~deb13u1_armhf-buildd.buildinfo 04eb9e84cd6b1d05ed3353fc6d12a942 53724 admin optional bubblewrap_0.12.0-1~deb13u1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEYxmcRLDHP0tCCM0oScpU3dYulLgFAmqPLqcACgkQScpU3dYu lLiqsQ/+PufoWQ4H2iNH63gn0qlYrsUP5hlAU+twtKiRkrKxNoxOLrNsvSkB4k01 uTlsB+OprSH6YDVAu/3M47lXtnXCOtiQfMqNMs+CoicIrtJphsmjUfV96zJ281+M xG993NsoQbmJtwp/ReUyi9tg0Tk3dlhWczG15+av1IL+Yvzu0zv1k2r+wsz/1N8G keuALSQlgBiaJhGjYMg6ZcrU0+8ea7hWFC3joaPhsnBtZaIwqy5afT89f8LRxeuS dy2feOMUGqYsNYWF6lq4MF8JOHiKeaL5TFRnREkj0uJJQNxGNHviW0Jv2Xr7CH77 DDSGWdfJLzRmF5jYzjhBGtjaRapwdzx/p0s+pzhD7cey8dOqOz3pdC2dS53vkAJQ 9a0cl1yZ/9NGt68glOTJVprXkWICh65X2Op/3jZYuxNQO254hVZcWWeud4sxvnxP XclI6zi+yPsWxFlUzYtp2lK2EhgG2ZJSPGH2lB4Efay/1xzMILmSKKBis5DO1nAJ Sjtx2QNErwtmYi1SXhYdBgDdPaTUXlYUnCtwRRQIN5PfAJ8HIrGfgogcrjYT4UI/ 0W0NycVN6CNMnxOG8+VyGM6jFI5qX06+CIQmIq92NpSLaIkCLV72U2N2gr3qGON4 ksauWNqe5t496KNQUBZLNg37OXigPzTELtoclv3pp+L3LQC2e6I= =s9xw -----END PGP SIGNATURE-----