Impact
A flaw in bubblewrap allows symlink traversal when creating files under a new root: the operation can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching user. This grant an attacker the ability to overwrite or create arbitrary files on the host before the sandboxed process starts. The weakness aligns with CWE-59, indicating improper restriction of filesystem operations, and could serve as a vector for privilege escalation or persistence.
Affected Systems
Affected installations include Red Hat Enterprise Linux 8, 9 and 10, as well as Red Hat Hardened Images that ship with bubblewrap. The vulnerability exists in any bubblewrap build prior to version 0.12.0, regardless of distribution; the Red Hat package updates for RHEL 8, 9 and 10 that provide 0.12.0 or later resolve the issue.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity: if the flaw is exploited, an attacker could write arbitrary files on the host system. While the EPSS score is not available and the flaw is not listed in the CISA KEV catalog, the vulnerability can be leveraged by anyone who can invoke bubblewrap – especially with setuid binaries – to perform the exploit during sandbox setup before the sandboxed process begins. Because the exploit requires only local file system access and the ability to run bubblewrap, its risk remains significant until mitigated.
OpenCVE Enrichment
Ubuntu USN