VendorsProject Atomicbubblewrapall versions
Vulnerabilities

Project Atomic Projectatomic Bubblewrap

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2017-5226
When executing a program via the bubblewrap sandbox, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the sandbox.
Published 2017-03-29 · Modified
10.0EPSS 0.032
CVE-2020-5291
Privilege escalation in setuid mode via user namespaces in Bubblewrap
Published 2020-03-31 · Modified
8.5EPSS 0.009
CVE-2019-12439
bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in /tmp as a mount point. In some particular configurations (related to XDG_RUNTIME_DIR), a local attacker may abuse this flaw to prevent other users from executing bubblewrap or potentially execute code.
Published 2019-05-29 · Modified
7.8EPSS 0.006