-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 26 Aug 2026 12:04:21 +0100 Source: bubblewrap Binary: bubblewrap bubblewrap-dbgsym Architecture: s390x Version: 0.12.0-1~deb13u1 Distribution: trixie-security Urgency: high Maintainer: s390x Build Daemon (ziehrer) Changed-By: Simon McVittie Description: bubblewrap - utility for unprivileged chroot and namespace manipulation Closes: 1145655 Changes: bubblewrap (0.12.0-1~deb13u1) trixie-security; urgency=high . * Merge new upstream release from unstable - Prevent sandbox escape via symlink traversal. If an app framework such as Flatpak mounts subdirectories into a directory controlled by the sandboxed app, a malicious or compromised sandboxed app could create symlinks in that directory to arrange for files/directories to be created on the host system. (GHSA-pxhw-h44j-8pfx, no known CVE ID; Closes: #1145655) - bubblewrap no longer supports running when setuid, matching the upstream default. This ensures that vulnerabilities similar to CVE-2026-41163 can't happen in future. * Debian 13 backport changes: - d/control, d/gbp.conf: Branch for Debian 13 stable updates - Revert packaging changes that are not appropriate for a stable release * Packaging changes since 0.11.0-2+deb13u1: - d/rules: Stop passing -Dsupport_setuid=false. The option no longer exists, and the new version of bubblewrap always behaves as though its value was false. - d/rules: Don't compile fallback code paths for kernel older than 5.10. This ensures that we're using the safest available mechanisms, using the openat2() syscall rather than emulating it in user-space. As a result, this version will not work on kernels older than the one found in Debian 11. - d/rules: Install NEWS.md as the upstream changelog - d/p/CVE-2026-41163/: Drop patches, no longer needed/applicable with the new upstream release - d/p/debian/Change-EPERM-error-message-to-show-Debian-specific-inform.patch: Adjust patch to apply to the new upstream release - d/README.Debian: Rewrite to reflect that setuid is no longer supported - d/copyright: Update license from LGPL-2+ to LGPL-2.1+, matching upstream Checksums-Sha1: 6a56979189bc37ee79505f644aa15c8af16ac0df 89604 bubblewrap-dbgsym_0.12.0-1~deb13u1_s390x.deb bf682ab289dedfe887f36d8e176a3d8edb406823 7850 bubblewrap_0.12.0-1~deb13u1_s390x-buildd.buildinfo 7672808cb86491ab9a740cb9467af36d5be4abe9 55676 bubblewrap_0.12.0-1~deb13u1_s390x.deb Checksums-Sha256: 0c8a2154f2b15f47dc1b710b6716a54a0d1f66d5b2e5660869fce8cad7910ac4 89604 bubblewrap-dbgsym_0.12.0-1~deb13u1_s390x.deb a3e2db65407d806478a44e7e809226cedca95dd778ad7b030d3d39749d1ddbfe 7850 bubblewrap_0.12.0-1~deb13u1_s390x-buildd.buildinfo 1eb0e98d9c6359b4f47c9360d4c5bd0ad5cef8721a2c97dc96b7f52abbb651d6 55676 bubblewrap_0.12.0-1~deb13u1_s390x.deb Files: 78249c34a0c2f9c2299cd07e7a1abf16 89604 debug optional bubblewrap-dbgsym_0.12.0-1~deb13u1_s390x.deb 695935a136d6d8c9615aed401789b00b 7850 admin optional bubblewrap_0.12.0-1~deb13u1_s390x-buildd.buildinfo b9cfcf835ec4c907f3b4c42287e8fc17 55676 admin optional bubblewrap_0.12.0-1~deb13u1_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEl0BM/nR+Oj597wRWMWUFebkHnoQFAmqPLowACgkQMWUFebkH noQxSxAAmjOwh5mU1Jc6EHBnldsefhSa4dLtCIwLDBYJySZvV8T+sj0c1NEvPPrq Ljcr4plQP2c0X8+kR3caHe764E7WeOJOWJpJP3IhcpxwyE8yDH4J5/oSy2SreC2+ XSQ6pwEcb6PjXZDg27s1MDdR9r3W5/WJ/v2YDigsCd2V03JwUK2m0rHalMxyAUdV 1INcGZT8daVdytof6W49f/VldTPuDxhviR04Q0s5E80v3zq0JWL58NeJll2fOkxf C+CgLZdrqxK8rALglN1jBl2S1ofS2Ki+hFLNXU4lgrG553Ue9gahs7TYZFAfIDpG T+/67D+UVChndigfFKWLwE8p3m3UUG2pJnvJHL8tdNbez9aF2Kv+1DSEO/oQPz/S kLQGW4zeVYreVI0W5vo4NIVQhPKZzR1dNw9IvUvMl7suc5PCr1bXeGMPqoTLwD9E Lzl5yx06smTp9yH02EaNqmiEZ9bQghf9pjsDjzvghPI/jdFedpdYZUzmhLO36UBL AHnrS2XlFg2YzWQk+0YNJEAjSDr/62jOSylFm6FtVvke/FMqkljxx3tX7svndJGS iQShh4AOw+mfoKn5Bf7nm5oBiuyD9R69V/5M/nkpQeN6ynu6UoeuCYEZ/Apjekyo KAvuSjPc2GkzbIP3jAPLZp4CcmN0hy2sc1ZENlx5dNl3neLL/OA= =HhGH -----END PGP SIGNATURE-----