Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41163

Опубликовано: 09 мая 2026
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

bubblewrap is a low-level unprivileged sandboxing tool. From version 0.11.0 to before version 0.11.2, if bubblewrap is installed in setuid mode then the user can use ptrace to attach to bubblewrap and control the unprivileged part of the sandbox setup phase. This allows the attacker to arbitrarily use the privileged operations, and in particular the "overlay mount" operation, allowing the creation of overlay mounts which is otherwise not allowed in the setuid version of bubblewrap. This issue has been patched in version 0.11.2.

A flaw was found in bubblewrap when operating in setuid mode. A local user may use ptrace to interfere with the sandbox setup process and gain access to privileged operations that are normally restricted. This could allow an attacker to bypass intended sandboxing restrictions and potentially elevate privileges on the system.

Отчет

This vulnerability affects bubblewrap's setuid mode. During sandbox initialization, insufficient isolation between privileged and unprivileged processing stages allows a local attacker to manipulate the sandbox setup process using ptrace.

The vulnerability relies on support for overlay filesystem mounts. The overlayfs mount support was added in bubblewrap version 0.11.0 and that versions prior to 0.11.0 do not support overlay mounts. Red Hat products currently ship bubblewrap versions that predate the introduction of overlay mount support. As a result, the vulnerable functionality is not present and Red Hat products are not affected by this issue.

Additionally, RHEL 8 and later install bubblewrap in non-setuid root mode by default. Since this vulnerability specifically affects the setuid mode, default Red Hat configurations should anyway will not expose to this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10bubblewrapNot affected
Red Hat Enterprise Linux 8bubblewrapNot affected
Red Hat Enterprise Linux 9bubblewrapNot affected
Red Hat OpenShift Container Platform 4rhcosNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-269
https://bugzilla.redhat.com/show_bug.cgi?id=2468439bubblewrap: bubblewrap: Privilege escalation via ptrace when installed in setuid mode

EPSS

Процентиль: 19%
0.00274
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
3 месяца назад

bubblewrap is a low-level unprivileged sandboxing tool. From version 0.11.0 to before version 0.11.2, if bubblewrap is installed in setuid mode then the user can use ptrace to attach to bubblewrap and control the unprivileged part of the sandbox setup phase. This allows the attacker to arbitrarily use the privileged operations, and in particular the "overlay mount" operation, allowing the creation of overlay mounts which is otherwise not allowed in the setuid version of bubblewrap. This issue has been patched in version 0.11.2.

CVSS3: 7
nvd
3 месяца назад

bubblewrap is a low-level unprivileged sandboxing tool. From version 0.11.0 to before version 0.11.2, if bubblewrap is installed in setuid mode then the user can use ptrace to attach to bubblewrap and control the unprivileged part of the sandbox setup phase. This allows the attacker to arbitrarily use the privileged operations, and in particular the "overlay mount" operation, allowing the creation of overlay mounts which is otherwise not allowed in the setuid version of bubblewrap. This issue has been patched in version 0.11.2.

CVSS3: 7
debian
3 месяца назад

bubblewrap is a low-level unprivileged sandboxing tool. From version 0 ...

suse-cvrf
3 месяца назад

Security update for bubblewrap

suse-cvrf
3 месяца назад

Security update for bubblewrap

EPSS

Процентиль: 19%
0.00274
Низкий

7 High

CVSS3