Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves one vulnerability can now be installed.. # Security update for bubblewrap Announcement ID: SUSE-SU-2026:21847-1 Release Date: 2026-05-26T09:51:49Z Rating: important References: * bsc#1263113 Cross-References: * CVE-2026-41163 CVSS scores: * CVE-2026-41163 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41163 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41163 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for bubblewrap fixes the following issue * CVE-2026-41163: improper process attachment via ptrace can lead to arbitrary privileged operations and local root escalation (bsc#1263113). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-801=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-801=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * bubblewrap-0.11.0-160000.3.1 * bubblewrap-debuginfo-0.11.0-160000.3.1 * bubblewrap-debugsource-0.11.0-160000.3.1 * bubblewrap-zsh-completion-0.11.0-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * bubblewrap-0.11.0-160000.3.1 * bubblewrap-debuginfo-0.11.0-160000.3.1 * bubblewrap-debugsource-0.11.0-160000.3.1 * bubblewrap-zsh-completion-0.11.0-160000.3.1 ## References: *https://www.suse.com/security/cve/CVE-2026-41163.html * https://bugzilla.suse.com/show_bug.cgi?id=1263113 . Important security update for bubblewrap addresses local root escalation risk with CVE-2026-41163 for SUSE customers.. SUSE bubblewrap security update local root escalation privilege. . Severity: Important. LinuxSecurity.com Team
Bubblewrap could be made to bypass sandbox restrictions.. ========================================================================== Ubuntu Security Notice USN-8288-1 May 20, 2026 bubblewrap vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 Summary: Bubblewrap could be made to bypass sandbox restrictions. Software Description: - bubblewrap: Low-level unprivileged sandboxing tool used by Flatpak and similar projects Details: It was discovered that Bubblewrap incorrectly handled the sandbox setup phase when installed in setuid mode. A local attacker could possibly use this issue to bypass sandbox restrictions. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS bubblewrap 0.11.1-1ubuntu0.1 Ubuntu 25.10 bubblewrap 0.11.0-2ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8288-1 CVE-2026-41163 Package Information: https://launchpad.net/ubuntu/+source/bubblewrap/0.11.1-1ubuntu0.1 https://launchpad.net/ubuntu/+source/bubblewrap/0.11.0-2ubuntu0.1 . Bubblewrap for Ubuntu has a low severity issue allowing potential sandbox bypass by local attackers. Update recommended.. bubblewrap ubuntu sandbox local attack security. . Severity: Low. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # bubblewrap-0.11.2-1.1 on GA media Announcement ID: openSUSE-SU-2026:10671-1 Rating: moderate Cross-References: * CVE-2026-41163 CVSS scores: * CVE-2026-41163 ( SUSE ): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41163 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the bubblewrap-0.11.2-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * bubblewrap 0.11.2-1.1 * bubblewrap-zsh-completion 0.11.2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41163.html . Moderate security update for openSUSE bubblewrap package to fix a critical vulnerability impacting data security.. openSUSE bubblewrap moderate update security. . LinuxSecurity.com Team
Access to files outside sandbox has been fixed in Flatpak, an application deployment framework for desktop apps. As a prerequisite for the fix, the bubblewrap package has also . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4099-1
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-9449 http://linux.oracle.com/errata/ELSA-2024-9449.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: bubblewrap-0.4.1-8.el9_5.x86_64.rpm flatpak-1.12.9-3.el9_5.x86_64.rpm flatpak-libs-1.12.9-3.el9_5.i686.rpm flatpak-libs-1.12.9-3.el9_5.x86_64.rpm flatpak-selinux-1.12.9-3.el9_5.noarch.rpm flatpak-session-helper-1.12.9-3.el9_5.x86_64.rpm flatpak-1.12.9-3.el9_5.i686.rpm flatpak-devel-1.12.9-3.el9_5.i686.rpm flatpak-devel-1.12.9-3.el9_5.x86_64.rpm flatpak-session-helper-1.12.9-3.el9_5.i686.rpm aarch64: bubblewrap-0.4.1-8.el9_5.aarch64.rpm flatpak-1.12.9-3.el9_5.aarch64.rpm flatpak-libs-1.12.9-3.el9_5.aarch64.rpm flatpak-selinux-1.12.9-3.el9_5.noarch.rpm flatpak-session-helper-1.12.9-3.el9_5.aarch64.rpm flatpak-devel-1.12.9-3.el9_5.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//bubblewrap-0.4.1-8.el9_5.src.rpm http://oss.oracle.com/ol9/SRPMS-updates//flatpak-1.12.9-3.el9_5.src.rpm Related CVEs: CVE-2024-42472 Description of changes: bubblewrap [0.4.1-8] - Backport upstream fix to help address CVE-2024-42472 in flatpak flatpak [1.12.9-3] - Fix previous changelog entry [1.12.9-2] - Backport upstream patches for CVE-2024-42472 - Require bubblewrap version that has new --bind-fd option backported for addressing CVE-2024-42472 _______________________________________________ El-errata mailing list
Important: bubblewrap and flatpak security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2024:9449", "synopsis": "Important: bubblewrap and flatpak security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for flatpak.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Bubblewrap (/usr/bin/bwrap) is a core execution engine for unprivileged containers that works as a setuid binary on kernels without user namespaces.\n\nSecurity Fix(es):\n\n* flatpak: Access to files outside sandbox for apps using persistent= (--persist) (CVE-2024-42472)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [], "cves": [{"name": "CVE-2024-42472", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-42472", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-11-19T16:02:19.758877Z", "rpms": {"Rocky Linux 9": {"nvras": ["flatpak-0:1.12.9-3.el9_4.aarch64.rpm", "flatpak-0:1.12.9-3.el9_4.i686.rpm", "flatpak-0:1.12.9-3.el9_4.ppc64le.rpm", "flatpak-0:1.12.9-3.el9_4.s390x.rpm", "flatpak-0:1.12.9-3.el9_4.src.rpm", "flatpak-0:1.12.9-3.el9_4.x86_64.rpm", "flatpak-debuginfo-0:1.12.9-3.el9_4.aarch64.rpm", "flatpak-debuginfo-0:1.12.9-3.el9_4.ppc64le.rpm", "flatpak-debuginfo-0:1.12.9-3.el9_4.s390x.rpm", "flatpak-debuginfo-0:1.12.9-3.el9_4.x86_64.rpm", "flatpak-debugsource-0:1.12.9-3.el9_4.aarch64.rpm", "flatpak-debugsource-0:1.12.9-3.el9_4.ppc64le.rpm", "flatpak-debugsource-0:1.12.9-3.el9_4.s390x.rpm", "flatpak-debugsource-0:1.12.9-3.el9_4.x86_64.rpm", "flatpak-devel-0:1.12.9-3.el9_4.aarch64.rpm", "flatpak-devel-0:1.12.9-3.el9_4.i686.rpm","flatpak-devel-0:1.12.9-3.el9_4.ppc64le.rpm", "flatpak-devel-0:1.12.9-3.el9_4.s390x.rpm", "flatpak-devel-0:1.12.9-3.el9_4.x86_64.rpm", "flatpak-libs-0:1.12.9-3.el9_4.aarch64.rpm", "flatpak-libs-0:1.12.9-3.el9_4.i686.rpm", "flatpak-libs-0:1.12.9-3.el9_4.ppc64le.rpm", "flatpak-libs-0:1.12.9-3.el9_4.s390x.rpm", "flatpak-libs-0:1.12.9-3.el9_4.x86_64.rpm", "flatpak-libs-debuginfo-0:1.12.9-3.el9_4.aarch64.rpm", "flatpak-libs-debuginfo-0:1.12.9-3.el9_4.ppc64le.rpm", "flatpak-libs-debuginfo-0:1.12.9-3.el9_4.s390x.rpm", "flatpak-libs-debuginfo-0:1.12.9-3.el9_4.x86_64.rpm", "flatpak-selinux-0:1.12.9-3.el9_4.noarch.rpm", "flatpak-session-helper-0:1.12.9-3.el9_4.aarch64.rpm", "flatpak-session-helper-0:1.12.9-3.el9_4.i686.rpm", "flatpak-session-helper-0:1.12.9-3.el9_4.ppc64le.rpm", "flatpak-session-helper-0:1.12.9-3.el9_4.s390x.rpm", "flatpak-session-helper-0:1.12.9-3.el9_4.x86_64.rpm", "flatpak-session-helper-debuginfo-0:1.12.9-3.el9_4.aarch64.rpm", "flatpak-session-helper-debuginfo-0:1.12.9-3.el9_4.ppc64le.rpm", "flatpak-session-helper-debuginfo-0:1.12.9-3.el9_4.s390x.rpm", "flatpak-session-helper-debuginfo-0:1.12.9-3.el9_4.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. A recent security update for Flatpak and Bubblewrap on Rocky Linux 9 resolves access challenges occurring beyond the confines of sandboxing. Make sure to stay informed!. RockyLinux, bubblewrap, flatpak, containerSecurity, accessControl. . Severity: Important. LinuxSecurity.com Team
Flatpak could be made to read and write files in locations it would not normally have access to.. ========================================================================== Ubuntu Security Notice USN-7046-1 September 30, 2024 bubblewrap, flatpak vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Flatpak could be made to read and write files in locations it would not normally have access to. Software Description: - bubblewrap: utility for unprivileged chroot and namespace manipulation - flatpak: Application deployment framework for desktop apps Details: It was discovered that Flatpak incorrectly handled certain persisted directories. An attacker could possibly use this issue to read and write files in locations it would not normally have access to. A patch was also needed to Bubblewrap in order to avoid race conditions caused by this fix. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS bubblewrap 0.9.0-1ubuntu0.1 flatpak 1.14.6-1ubuntu0.1 libflatpak0 1.14.6-1ubuntu0.1 Ubuntu 22.04 LTS bubblewrap 0.6.1-1ubuntu0.1 flatpak 1.12.7-1ubuntu0.1 libflatpak0 1.12.7-1ubuntu0.1 Ubuntu 20.04 LTS bubblewrap 0.4.0-1ubuntu4.1 flatpak 1.6.5-0ubuntu0.5 libflatpak0 1.6.5-0ubuntu0.5 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7046-1 CVE-2024-42472, https://bugs.launchpad.net/ubuntu/+source/flatpak/+bug/2077087 Package Information: https://launchpad.net/ubuntu/+source/bubblewrap/0.9.0-1ubuntu0.1 https://launchpad.net/ubuntu/+source/flatpak/1.14.6-1ubuntu0.1 https://launchpad.net/ubuntu/+source/bubblewrap/0.6.1-1ubuntu0.1 https://launchpad.net/ubuntu/+source/flatpak/1.12.7-1ubuntu0.1 https://launchpad.net/ubuntu/+source/bubblewrap/0.4.0-1ubuntu4.1 https://launchpad.net/ubuntu/+source/flatpak/1.6.5-0ubuntu0.5 . Ubuntu has released a security advisory focusing on vulnerabilities within Flatpak and Bubblewrap, aimed at strengthening file access security measures. Immediate updates are recommended.. Ubuntu Security, Flatpak Update, Bubblewrap Fix, File Access Vulnerability. . LinuxSecurity.com Team
flatpak 1.15.10 and bubblewrap 0.10.0 updates, which together fix CVE-2024-42472 in Flatpak.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-03fd821ae2 2024-09-15 02:26:50.032592 -------------------------------------------------------------------------------- Name : flatpak Product : Fedora 39 Version : 1.15.10 Release : 1.fc39 URL : https://flatpak.org/ Summary : Application deployment framework for desktop apps Description : flatpak is a system for building, distributing and running sandboxed desktop applications on Linux. See https://wiki.gnome.org/Projects/SandboxedApps for more information. -------------------------------------------------------------------------------- Update Information: flatpak 1.15.10 and bubblewrap 0.10.0 updates, which together fix CVE-2024-42472 in Flatpak. -------------------------------------------------------------------------------- ChangeLog: * Fri Aug 30 2024 Kalev Lember - 1.15.10-1 - Update to 1.15.10 (#2299621) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2271977 - bubblewrap-0.10.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2271977 [ 2 ] Bug #2299621 - flatpak-1.15.10 is available https://bugzilla.redhat.com/show_bug.cgi?id=2299621 [ 3 ] Bug #2305286 - CVE-2024-42472 flatpak: Access to files outside sandbox for apps using persistent= (--persist) [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2305286 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-03fd821ae2' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key.More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.