[From nobody Mon Aug 31 14:49:08 2026
Received: (at 1145655-close) by bugs.debian.org; 31 Aug 2026 13:47:08 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-114.1 required=4.0 tests=ALL_TRUSTED,BAYES_00,
 DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FOURLA,
 FVGT_m_MULTI_ODD,HAS_BUG_NUMBER,MD5_SHA1_SUM,PGPSIGNATURE,
 SPF_HELO_PASS,SPF_PASS,USER_IN_DKIM_WELCOMELIST autolearn=ham
 autolearn_force=no version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 64; hammy, 150; neutral, 299; spammy,
 0. spammytokens: hammytokens:0.000-+--HX-Debian:DAK,
 0.000-+--H*rp:D*ftp-master.debian.org, 0.000-+--UD:debian.tar.xz,
 0.000-+--H*r:sk:fasolo., 0.000-+--H*MI:fasolo
Return-path: &lt;envelope@ftp-master.debian.org&gt;
Received: from mailly.debian.org ([2001:41b8:202:deb:6564:a62:52c3:4b72]:33820)
 by buxtehude.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1x12Ls-007OLk-0j for 1145655-close@bugs.debian.org;
 Mon, 31 Aug 2026 13:47:08 +0000
Received: via submission
 from C=NA, ST=NA, L=Ankh Morpork, O=Debian SMTP, OU=Debian SMTP CA,
 CN=fasolo.debian.org, EMAIL=hostmaster@fasolo.debian.org (verified)
 by mailly.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1x12Lq-007ugJ-2V for 1145655-close@bugs.debian.org;
 Mon, 31 Aug 2026 13:47:06 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
 d=ftp-master.debian.org; s=smtpauto.fasolo; h=Date:Message-Id:Content-Type:
 Subject:MIME-Version:To:Reply-To:From:Cc:Content-Transfer-Encoding:Content-ID
 :Content-Description:In-Reply-To:References;
 bh=2WvWQI7r/AsTSIOF9/77ZxVWhAO8MU91YtzPDBBdN0o=; b=tJ8eti2fymmzCCb/CaAZzZrm2K
 yB1xnY2V6/IdOgw8aGLac+Y3G/QY665ZbhA5pBFQtMxlST3AOSDh5uIzSbEGadfhY0UngSZYRlV3L
 IWITj4q2eyn7emADW+xvjbbCT0DNEZuuh9KtIZQrFy1ZxOgjr7ImPIK/00b7EjTSSywaX7TMekOxo
 b2CFlZC1bWzjzsk9hF9kODi/k8wUtVShCyQY+4zkIJY8jyakiLitdkm8KwdE69kKe9pIsYz91aiCy
 wK15X6pixLZoi3Lfr19adTdo3sne4LUomhtPk96BiLykgO5gVCRAcEDy5ZsfC0Z5oEXt5lpj6gBrG
 mfYKpyNw==;
Received: from dak by fasolo.debian.org with local (Exim 4.98.2)
 (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1x12Lp-000000050Aq-3oue; Mon, 31 Aug 2026 13:47:05 +0000
From: Debian FTP Masters &lt;ftpmaster@ftp-master.debian.org&gt;
Reply-To: Simon McVittie &lt;smcv@debian.org&gt;
To: 1145655-close@bugs.debian.org
X-DAK: dak process-policy
X-Debian: DAK
X-Debian-Package: bubblewrap
Debian: DAK
Debian-Changes: bubblewrap_0.12.0-1~deb13u1_source.changes
Debian-Source: bubblewrap
Debian-Version: 0.12.0-1~deb13u1
Debian-Architecture: source
Debian-Suite: proposed-updates
Debian-Archive-Action: accept
MIME-Version: 1.0
Subject: Bug#1145655: fixed in bubblewrap 0.12.0-1~deb13u1
Content-Type: multipart/signed; micalg=&quot;pgp-sha256&quot;;
 protocol=&quot;application/pgp-signature&quot;;
 boundary=&quot;===============4462695239269012115==&quot;
Message-Id: &lt;E1x12Lp-000000050Aq-3oue@fasolo.debian.org&gt;
Date: Mon, 31 Aug 2026 13:47:05 +0000

--===============4462695239269012115==
Content-Type: text/plain; charset=&quot;utf-8&quot;
Content-Transfer-Encoding: quoted-printable

Source: bubblewrap
Source-Version: 0.12.0-1~deb13u1
Done: Simon McVittie &lt;smcv@debian.org&gt;

We believe that the bug you reported is fixed in the latest version of
bubblewrap, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1145655@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Simon McVittie &lt;smcv@debian.org&gt; (supplier of updated bubblewrap package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Wed, 26 Aug 2026 12:04:21 +0100
Source: bubblewrap
Architecture: source
Version: 0.12.0-1~deb13u1
Distribution: trixie-security
Urgency: high
Maintainer: Utopia Maintenance Team &lt;pkg-utopia-maintainers@lists.alioth.debi=
an.org&gt;
Changed-By: Simon McVittie &lt;smcv@debian.org&gt;
Closes: 1145655
Changes:
 bubblewrap (0.12.0-1~deb13u1) trixie-security; urgency=3Dhigh
 .
   * Merge new upstream release from unstable
     - Prevent sandbox escape via symlink traversal.
       If an app framework such as Flatpak mounts subdirectories into a
       directory controlled by the sandboxed app, a malicious or compromised
       sandboxed app could create symlinks in that directory to arrange for
       files/directories to be created on the host system.
       (GHSA-pxhw-h44j-8pfx, no known CVE ID; Closes: #1145655)
     - bubblewrap no longer supports running when setuid, matching the
       upstream default. This ensures that vulnerabilities similar to
       CVE-2026-41163 can't happen in future.
   * Debian 13 backport changes:
     - d/control, d/gbp.conf: Branch for Debian 13 stable updates
     - Revert packaging changes that are not appropriate for a stable release
   * Packaging changes since 0.11.0-2+deb13u1:
     - d/rules: Stop passing -Dsupport_setuid=3Dfalse.
       The option no longer exists, and the new version of bubblewrap always
       behaves as though its value was false.
     - d/rules: Don't compile fallback code paths for kernel older than 5.10.
       This ensures that we're using the safest available mechanisms,
       using the openat2() syscall rather than emulating it in user-space.
       As a result, this version will not work on kernels older than the
       one found in Debian 11.
     - d/rules: Install NEWS.md as the upstream changelog
     - d/p/CVE-2026-41163/:
       Drop patches, no longer needed/applicable with the new upstream release
     - d/p/debian/Change-EPERM-error-message-to-show-Debian-specific-inform.p=
atch:
       Adjust patch to apply to the new upstream release
     - d/README.Debian: Rewrite to reflect that setuid is no longer supported
     - d/copyright: Update license from LGPL-2+ to LGPL-2.1+, matching upstre=
am
 .
 bubblewrap (0.12.0-1) unstable; urgency=3Dhigh
 .
   * New upstream release
     - Prevent sandbox escape via symlink traversal.
       If an app framework such as Flatpak mounts subdirectories into a
       directory controlled by the sandboxed app, a malicious or compromised
       sandboxed app could create symlinks in that directory to arrange for
       files/directories to be created on the host system.
       (GHSA-pxhw-h44j-8pfx, no known CVE ID; Closes: #1145655)
     - d/rules: Stop passing -Dsupport_setuid=3Dfalse.
       The option no longer exists, and the new version of bubblewrap always
       behaves as though its value was false.
     - d/copyright: Update license from LGPL-2+ to LGPL-2.1+, matching upstre=
am
     - d/p/debian/Change-EPERM-error-message-to-show-Debian-specific-inform.p=
atch:
       Adjust patch to apply to the new upstream release
   * d/rules: Don't compile fallback code paths for kernel older than 5.10.
     This ensures that we're using the safest available mechanisms,
     using the openat2() syscall rather than emulating it in user-space.
     As a result, this version will not work on kernels older than the
     one found in Debian 11.
 .
 bubblewrap (0.11.2-2) unstable; urgency=3Dmedium
 .
   * d/rules: Stop allowing bubblewrap to run when setuid, matching
     the upstream default. This ensures that vulnerabilities similar to
     CVE-2026-41163 can't happen in future.
   * d/control, d/NEWS, d/README.Debian: Update documentation accordingly
   * Standards-Version: 4.7.4 (no changes required)
Checksums-Sha1:
 5518fac2bbaa07b5ad6bf907ab868427a1aaf308 2362 bubblewrap_0.12.0-1~deb13u1.dsc
 183eaff6b078c1ea5ad55271e7d1fa5c8c0d339e 126452 bubblewrap_0.12.0.orig.tar.xz
 87adaf7ecab19c7df09837dfeb347955405975d5 13728 bubblewrap_0.12.0-1~deb13u1.d=
ebian.tar.xz
 9e0e7b7df67852aa5f0be41bbe4a061b30fa5967 7637 bubblewrap_0.12.0-1~deb13u1_so=
urce.buildinfo
Checksums-Sha256:
 1abef77e6c35ce6c48c8969d31bffcc7a589bfd8e8fea9284fd8d77750f01d39 2362 bubble=
wrap_0.12.0-1~deb13u1.dsc
 9760d007363e3abba7c747489910f9f82d9fca53ba3bd3282e396fa3c97a3314 126452 bubb=
lewrap_0.12.0.orig.tar.xz
 7b54f121aebf5d4b38360ea728274c26fa471582bc3e6658379b679ecd8b5a2f 13728 bubbl=
ewrap_0.12.0-1~deb13u1.debian.tar.xz
 6d706aa8b531e8f0745e3cbc6fb0ecb26c8900bdb3813b31b69ccedb0fde72c0 7637 bubble=
wrap_0.12.0-1~deb13u1_source.buildinfo
Files:
 66e88b791517fe7ae3dfcb496c7ec5f9 2362 admin optional bubblewrap_0.12.0-1~deb=
13u1.dsc
 323b059c9599b60b456bcf9e9800ff44 126452 admin optional bubblewrap_0.12.0.ori=
g.tar.xz
 d804b9f84c9ed92fe0d912b40d61eb84 13728 admin optional bubblewrap_0.12.0-1~de=
b13u1.debian.tar.xz
 a9d0fd1cc18535a41cbd0032fa25eb54 7637 admin optional bubblewrap_0.12.0-1~deb=
13u1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmqPKX8ACgkQEMKTtsN8
TjaD7Q//bOPiMak9bDOKeQEFXP4vhJ79AnyXrhr79FFHth6vIYXx570UVozkkku7
gzQe7I8kgrVwp0wmXvG/ySyguyZ5MV1BuovoCvDzsLDcJBrKMlZ/nUGIrWRJJYBa
km2d0y2/kgNTcA1oZyr2CpRiU14xFmrRiJHfStKln3XoDy2cy7RYTSltIScUopz1
rsEHvYX7Lqp8slW684q2rsW9ueSYeVwNyu8axlSgzcpwmG+92RyrAEVdXq7/z+xS
KBZqND+itbDLhrbHsq1yJU/wxDYgRiYP02mAHrHsXn0w91P9zLUhGxRMUHLIto8j
n5mPMheDFBZUgKfNwK4VHyPiYzZoE9B3jh9mJshABtWCRBpYnQCqHZ7qkM72z/Su
kRYFIXReZbSSrFG5CtknvUhwkwgysVOWC1CUyIitr3R7ASsvzO7UlgM5JuCB3U7U
B+0LnrHJ+opvmdxMMTqxRBi4nirGANi6GxuWSoFmVnD65upiuoZbhX3RDjwnXLe3
MMmvpuRHSGMlpeCREemy0ndV4hBwEICjogfzUMI8qHL56AmqfwX/6OcsGsCfw4Wa
GRBZ37hyrkc6my9R9qOwbH0z5ZZPtdZVaQtqHnnqS09llyoXzWIPlf6hU1irZ1M0
EDUqiDdoMhRiXI38XfJdbez1wq1+xoqTmRtVa03RCUOz4UhN3HY=3D
=3DXSuk
-----END PGP SIGNATURE-----


--===============4462695239269012115==
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----

iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCapWF2QAKCRCb9qggYcy5
ITUoAQD17BjA/hIPBJvLkpip3MDgxGb5JyWkgMnhIFacBjQj9AD/TaQU18tmUBom
ZZneXvNp1gQ5JQs8fFlh0Ti2d/S/5gE=
=K9Tb
-----END PGP SIGNATURE-----

--===============4462695239269012115==--
]