[Git][security-tracker-team/security-tracker][master] bubblewrap CVEfied

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Sep 9 11:08:00 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
9d7ee3fb by Moritz Muehlenhoff at 2026-09-09T12:06:54+02:00
bubblewrap CVEfied

- - - - -


2 changed files:

- data/CVE/list
- data/DSA/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -15161,9 +15161,8 @@ CVE-2025-10903 (GitLab has remediated an issue in GitLab EE affecting all versio
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2023-42179 (Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect A ...)
 	NOT-FOR-US: Bird Home Automation
-CVE-2026-XXXX [GHSA-pxhw-h44j-8pfx: sandbox escape via symlink traversal during setup]
+CVE-2026-87766 [GHSA-pxhw-h44j-8pfx: sandbox escape via symlink traversal during setup]
 	- bubblewrap 0.12.0-1 (bug #1145655)
-	[trixie] - bubblewrap 0.12.0-1~deb13u1
 	[bookworm] - bubblewrap <ignored> (Intrusive backport due to a complete rewrite)
 	[bullseye] - bubblewrap <ignored> (Intrusive backport due to a complete rewrite)
 	NOTE: https://github.com/containers/bubblewrap/security/advisories/GHSA-pxhw-h44j-8pfx


=====================================
data/DSA/list
=====================================
@@ -55,6 +55,7 @@
 	{CVE-2026-14380 CVE-2026-14739 CVE-2026-14740 CVE-2026-15043 CVE-2026-15392 CVE-2026-60081 CVE-2026-60082 CVE-2026-73193 CVE-2026-73194}
 	[trixie] - libdbi-perl 1.652-2~deb13u1
 [27 Aug 2026] DSA-6472-1 bubblewrap - security update
+	{CVE-2026-87766}
 	[trixie] - bubblewrap 0.12.0-1~deb13u1
 [27 Aug 2026] DSA-6471-1 wireshark - security update
 	{CVE-2026-15163 CVE-2026-15164 CVE-2026-15166 CVE-2026-15167 CVE-2026-15168 CVE-2026-15169 CVE-2026-15170 CVE-2026-15171 CVE-2026-15172 CVE-2026-15174 CVE-2026-76879 CVE-2026-76880 CVE-2026-76881 CVE-2026-76882 CVE-2026-76883 CVE-2026-76884 CVE-2026-76885 CVE-2026-76886 CVE-2026-76887 CVE-2026-76888 CVE-2026-76889 CVE-2026-76890 CVE-2026-76891 CVE-2026-76917 CVE-2026-76918 CVE-2026-76919 CVE-2026-76920 CVE-2026-76921 CVE-2026-76922 CVE-2026-76923 CVE-2026-76924 CVE-2026-76926 CVE-2026-76927 CVE-2026-76928 CVE-2026-76929}



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9d7ee3fba899ca18ca66a12b6d9eda3cb9fc575e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9d7ee3fba899ca18ca66a12b6d9eda3cb9fc575e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260909/8680ca7d/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list