-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 26 Aug 2026 12:04:21 +0100 Source: bubblewrap Binary: bubblewrap bubblewrap-dbgsym Architecture: riscv64 Version: 0.12.0-1~deb13u1 Distribution: trixie-security Urgency: high Maintainer: riscv64 Build Daemon (rv-osuosl-01) Changed-By: Simon McVittie Description: bubblewrap - utility for unprivileged chroot and namespace manipulation Closes: 1145655 Changes: bubblewrap (0.12.0-1~deb13u1) trixie-security; urgency=high . * Merge new upstream release from unstable - Prevent sandbox escape via symlink traversal. If an app framework such as Flatpak mounts subdirectories into a directory controlled by the sandboxed app, a malicious or compromised sandboxed app could create symlinks in that directory to arrange for files/directories to be created on the host system. (GHSA-pxhw-h44j-8pfx, no known CVE ID; Closes: #1145655) - bubblewrap no longer supports running when setuid, matching the upstream default. This ensures that vulnerabilities similar to CVE-2026-41163 can't happen in future. * Debian 13 backport changes: - d/control, d/gbp.conf: Branch for Debian 13 stable updates - Revert packaging changes that are not appropriate for a stable release * Packaging changes since 0.11.0-2+deb13u1: - d/rules: Stop passing -Dsupport_setuid=false. The option no longer exists, and the new version of bubblewrap always behaves as though its value was false. - d/rules: Don't compile fallback code paths for kernel older than 5.10. This ensures that we're using the safest available mechanisms, using the openat2() syscall rather than emulating it in user-space. As a result, this version will not work on kernels older than the one found in Debian 11. - d/rules: Install NEWS.md as the upstream changelog - d/p/CVE-2026-41163/: Drop patches, no longer needed/applicable with the new upstream release - d/p/debian/Change-EPERM-error-message-to-show-Debian-specific-inform.patch: Adjust patch to apply to the new upstream release - d/README.Debian: Rewrite to reflect that setuid is no longer supported - d/copyright: Update license from LGPL-2+ to LGPL-2.1+, matching upstream Checksums-Sha1: c5816d0bb0ab1ce0aa191459c1f3d37d61d8a8fc 85376 bubblewrap-dbgsym_0.12.0-1~deb13u1_riscv64.deb 69fa4b49241b779ae528f24e8d893c268e7eb91a 7932 bubblewrap_0.12.0-1~deb13u1_riscv64-buildd.buildinfo b4319f941fc0210b0bf42da160c5633d6a20c73d 55872 bubblewrap_0.12.0-1~deb13u1_riscv64.deb Checksums-Sha256: 80cbbb0298dabf5f4f19627889d650355bf036a235f767f66f3f1ddb29b5afc7 85376 bubblewrap-dbgsym_0.12.0-1~deb13u1_riscv64.deb 927a05dd59bc74168db7105d63bd9b5c2220f9cbdd01bbeb89ae692303e18fee 7932 bubblewrap_0.12.0-1~deb13u1_riscv64-buildd.buildinfo dc6051006d5ec6c6e871c263477699f2cb313303632f7ac85efa6dad27add924 55872 bubblewrap_0.12.0-1~deb13u1_riscv64.deb Files: 5dee35ec7a2925b2fb202f3a5c44ddba 85376 debug optional bubblewrap-dbgsym_0.12.0-1~deb13u1_riscv64.deb 132a2e93204e21e6a0902e8b608d2926 7932 admin optional bubblewrap_0.12.0-1~deb13u1_riscv64-buildd.buildinfo abd1279e6a39c8e948493e3dfd2ae258 55872 admin optional bubblewrap_0.12.0-1~deb13u1_riscv64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE3smN1vgomTkXJcrkIhSPlPtgqxkFAmqPNFQACgkQIhSPlPtg qxk55RAAsltlv5ar7a+6OkRwxGVa2UK6/FGLVefWkFAvGkjSmWkcGun0n9j4q5rA ut8HQKL7P1DDjHWkf+8MsrytT7xV2pxrYd5onFwiM39MGAOSwwh+YZEjJl9Kfk68 k2K1w1mk+NzwB+Y1f+kAwTgD3LxY2XG8jrzRzcK2nAunEOkLz7uPMDvb/aQwggeh VUU3dvzXtA/oB9OE4TW0CYeALLlveUYJBJqe+Msk9hvUPCH5B/7ftp0ywgM9ceAT 5DcsGaAjs/rAtNRnWaaMIpm+U0/d+P00LlARlE9YUFxBFIvvCta3pMjBqJf3gKbC aYWBUJwvDfDqkmlzONl65yXRYUtopg6PxNMqHdJmAmuQ8xBL9fur3d7XeMNNmn+u B0ZwaAjYX0YRlbzOmEVnNR7HwKI2zkM+nuxYRvg61eudzBaZAk4PfUtsnAKa2Ixo VJ512QaAYa8unr7HASKVihFXyhTRfa+2cRqGSg0/lGK+Ltv7wBPIASQkNiDoFSlv BjyPTKOfDigaknDqX7WIT61oCWSpO59By2Z7Ny2tkcgUuzH45vrvB9iL3qH/2p6A zUrsVsQVI6ndg8tW9qO42YnwRDgduiLuIk21SuQw7UHdsjVvPhH8g+1T65i9f5qn QsWjUfjxgX4vW04S2MzV6PTxE7INrjfZoGVYz72W2jK2Uf1QNrQ= =JMJQ -----END PGP SIGNATURE-----