Description
A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching user. This happens before the sandboxed process starts. This issue is GHSA-pxhw-h44j-8pfx. It is fixed in bubblewrap 0.12.0.
Published: 2026-09-09
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Write files outside sandbox during setup, allowing potential privilege escalation or system modification
Action: Patch immediately
AI Analysis

Impact

A flaw in bubblewrap allows symlink traversal when creating files under a new root: the operation can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching user. This grant an attacker the ability to overwrite or create arbitrary files on the host before the sandboxed process starts. The weakness aligns with CWE-59, indicating improper restriction of filesystem operations, and could serve as a vector for privilege escalation or persistence.

Affected Systems

Affected installations include Red Hat Enterprise Linux 8, 9 and 10, as well as Red Hat Hardened Images that ship with bubblewrap. The vulnerability exists in any bubblewrap build prior to version 0.12.0, regardless of distribution; the Red Hat package updates for RHEL 8, 9 and 10 that provide 0.12.0 or later resolve the issue.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity: if the flaw is exploited, an attacker could write arbitrary files on the host system. While the EPSS score is not available and the flaw is not listed in the CISA KEV catalog, the vulnerability can be leveraged by anyone who can invoke bubblewrap – especially with setuid binaries – to perform the exploit during sandbox setup before the sandboxed process begins. Because the exploit requires only local file system access and the ability to run bubblewrap, its risk remains significant until mitigated.

Generated by OpenCVE AI on September 9, 2026 at 10:31 UTC.

Remediation

Vendor Workaround

Do not create files on untrusted content with unpatched bwrap. Do not install untrusted Flatpaks. No upstream fix for older setuid builds.


OpenCVE Recommended Actions

  • Upgrade bubblewrap to version 0.12.0 or newer.
  • Avoid creating files on untrusted content with unpatched bwrap and refrain from installing untrusted Flatpaks until the update is applied.
  • If setuid versions of bubblewrap cannot be replaced, restrict their use to trusted environments or disable the setuid bit.

Generated by OpenCVE AI on September 9, 2026 at 10:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8779-1 Bubblewrap vulnerabilities
History

Tue, 22 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
References

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat hardened Images
Vendors & Products Redhat hardened Images

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
References

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Wed, 09 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching user. This happens before the sandboxed process starts. This issue is GHSA-pxhw-h44j-8pfx. It is fixed in bubblewrap 0.12.0.
Title Bubblewrap: bubblewrap: symlink traversal via /oldroot allows writing files outside sandbox during setup
First Time appeared Redhat
Redhat enterprise Linux
Redhat hummingbird
Weaknesses CWE-59
CPEs cpe:/a:redhat:hummingbird:1
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat hummingbird
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Redhat Enterprise Linux Hardened Images Hummingbird
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-22T23:07:02.744Z

Reserved: 2026-09-09T08:08:33.568Z

Link: CVE-2026-87766

cve-icon Vulnrichment

Updated: 2026-09-22T23:07:02.744Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-09T09:17:12.540

Modified: 2026-09-22T23:17:07.763

Link: CVE-2026-87766

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-09T00:00:00Z

Links: CVE-2026-87766 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:01:52Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')