Home / mailings [SECURITY] [DSA 6472-1] bubblewrap security update
Posted on 27 August 2026
Debian Security Advisory- -------------------------------------------------------------------------
Debian Security Advisory DSA-6472-1 security@debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
August 27, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : bubblewrap
CVE ID : not yet available
Debian Bug : 1145655
A symlink traversal vulnerability was discovered in bubblewrap, a
low-level unprivileged sandboxing tool used by Flatpak and other
projects, which could result in sandbox escape by malicious/compromised
Flatpak apps.
For the stable distribution (trixie), this problem has been fixed in
version 0.12.0-1~deb13u1. This updates bubblewrap to the 0.12 release
branch, which no longer supports running bubblewrap as setuid root.
For additional details please refer to the README.Debian.gz file.
We recommend that you upgrade your bubblewrap packages.
For the detailed security status of bubblewrap please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/bubblewrap
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
