* [Buildroot] [PATCH] package/bubblewrap: security bump to version 0.12.0
@ 2026-09-10 9:52 Adrian Perez de Castro
2026-09-10 20:01 ` Julien Olivain via buildroot
2026-09-11 13:32 ` Peter Korsgaard
0 siblings, 2 replies; 5+ messages in thread
From: Adrian Perez de Castro @ 2026-09-10 9:52 UTC (permalink / raw)
To: buildroot; +Cc: Adrian Perez de Castro
Fixes a sandbox escape through symlink traversal tracked in
CVE-2026-87766, which affects all previous versions.
Using the bwrap binary with the setuid bit set is no longer supported
and user namespaces are now always required, so a kernel config fixup
is applied.
A new build option allows indicating the minimum kernel version that
will be used, which removes code used for backwards compatibility with
kernels older than 5.6.0 when a newer version is specified. Passing
$(LINUX_VERSION_PROBED) seems reasonable here.
This version also changed the license from LGPL-2.0+ to LGPL-2.1+,
hence the updated hash.
Release notes:
https://github.com/containers/bubblewrap/releases/tag/v0.12.0
Signed-off-by: Adrian Perez de Castro <aperez@igalia.com>
---
package/bubblewrap/bubblewrap.hash | 6 +++---
package/bubblewrap/bubblewrap.mk | 17 +++++++----------
2 files changed, 10 insertions(+), 13 deletions(-)
diff --git a/package/bubblewrap/bubblewrap.hash b/package/bubblewrap/bubblewrap.hash
index e87d3c81cb..e150e1495d 100644
--- a/package/bubblewrap/bubblewrap.hash
+++ b/package/bubblewrap/bubblewrap.hash
@@ -1,5 +1,5 @@
-# From https://github.com/containers/bubblewrap/releases/download/v0.11.2/bubblewrap-0.11.2.tar.xz.sha256sum
-sha256 69abc30005d2186baf7737feacd8da35633b93cf5af38838ecff17c5f8e924f6 bubblewrap-0.11.2.tar.xz
+# From https://github.com/containers/bubblewrap/releases/download/v0.12.0/bubblewrap-0.12.0.tar.xz.sha256sum
+sha256 9760d007363e3abba7c747489910f9f82d9fca53ba3bd3282e396fa3c97a3314 bubblewrap-0.12.0.tar.xz
# Hash for license files:
-sha256 b7993225104d90ddd8024fd838faf300bea5e83d91203eab98e29512acebd69c COPYING
+sha256 dc626520dcd53a22f727af3ee42c770e56c97a64fe3adb063799d8ab032fe551 COPYING
diff --git a/package/bubblewrap/bubblewrap.mk b/package/bubblewrap/bubblewrap.mk
index 7838ab90b3..40a8148e14 100644
--- a/package/bubblewrap/bubblewrap.mk
+++ b/package/bubblewrap/bubblewrap.mk
@@ -4,21 +4,24 @@
#
################################################################################
-BUBBLEWRAP_VERSION = 0.11.2
+BUBBLEWRAP_VERSION = 0.12.0
BUBBLEWRAP_SITE = https://github.com/containers/bubblewrap/releases/download/v$(BUBBLEWRAP_VERSION)
BUBBLEWRAP_SOURCE = bubblewrap-$(BUBBLEWRAP_VERSION).tar.xz
BUBBLEWRAP_DEPENDENCIES = host-pkgconf libcap
-BUBBLEWRAP_LICENSE = LGPL-2.0+
+BUBBLEWRAP_LICENSE = LGPL-2.1+
BUBBLEWRAP_LICENSE_FILES = COPYING
BUBBLEWRAP_CPE_ID_VENDOR = projectatomic
+define BUBBLEWRAP_CONFIG_FIXUPS
+ $(call KCONFIG_ENABLE_OPT,CONFIG_USER_NS)
+endef
+
BUBBLEWRAP_CONF_OPTS = \
+ -Dassume_kernel=$(LINUX_VERSION_PROBED) \
-Dzsh_completion=disabled \
-Dman=disabled \
-Dpython=$(HOST_DIR)/bin/python \
- -Drequire_userns=false \
- -Dsupport_setuid=true \
-Dtests=false
ifeq ($(BR2_PACKAGE_BASH_COMPLETION),y)
@@ -36,10 +39,4 @@ else
BUBBLEWRAP_CONF_OPTS += -Dselinux=disabled
endif
-# We need to mark bwrap as setuid, in case the kernel
-# has user namespaces disabled for non-root users.
-define BUBBLEWRAP_PERMISSIONS
- /usr/bin/bwrap f 1755 0 0 - - - - -
-endef
-
$(eval $(meson-package))
--
2.55.0
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot
^ permalink raw reply related [flat|nested] 5+ messages in thread
* Re: [Buildroot] [PATCH] package/bubblewrap: security bump to version 0.12.0
2026-09-10 9:52 [Buildroot] [PATCH] package/bubblewrap: security bump to version 0.12.0 Adrian Perez de Castro
@ 2026-09-10 20:01 ` Julien Olivain via buildroot
2026-09-11 0:07 ` Adrian Perez de Castro
2026-09-11 13:32 ` Peter Korsgaard
1 sibling, 1 reply; 5+ messages in thread
From: Julien Olivain via buildroot @ 2026-09-10 20:01 UTC (permalink / raw)
To: Adrian Perez de Castro; +Cc: buildroot
On 10/09/2026 11:52, Adrian Perez de Castro wrote:
> Fixes a sandbox escape through symlink traversal tracked in
> CVE-2026-87766, which affects all previous versions.
>
> Using the bwrap binary with the setuid bit set is no longer supported
> and user namespaces are now always required, so a kernel config fixup
> is applied.
>
> A new build option allows indicating the minimum kernel version that
> will be used, which removes code used for backwards compatibility with
> kernels older than 5.6.0 when a newer version is specified. Passing
> $(LINUX_VERSION_PROBED) seems reasonable here.
>
> This version also changed the license from LGPL-2.0+ to LGPL-2.1+,
> hence the updated hash.
>
> Release notes:
>
> https://github.com/containers/bubblewrap/releases/tag/v0.12.0
>
> Signed-off-by: Adrian Perez de Castro <aperez@igalia.com>
Applied to master, thanks. For info, I fixed the linux config fixup (no
pun intended). The "_LINUX" was missing and the fixup was not applied.
See:
https://gitlab.com/buildroot.org/buildroot/-/commit/4cb6193d2eca39b1bd79ff4867c842f507f692b8
Best regards.
Julien.
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [Buildroot] [PATCH] package/bubblewrap: security bump to version 0.12.0
2026-09-10 20:01 ` Julien Olivain via buildroot
@ 2026-09-11 0:07 ` Adrian Perez de Castro
0 siblings, 0 replies; 5+ messages in thread
From: Adrian Perez de Castro @ 2026-09-11 0:07 UTC (permalink / raw)
To: Julien Olivain; +Cc: Julien Olivain via buildroot, buildroot
[-- Attachment #1.1: Type: text/plain, Size: 1285 bytes --]
Hello Julien,
On Thu, 10 Sep 2026 22:01:38 +0200 Julien Olivain via buildroot <buildroot@buildroot.org> wrote:
> On 10/09/2026 11:52, Adrian Perez de Castro wrote:
> > Fixes a sandbox escape through symlink traversal tracked in
> > CVE-2026-87766, which affects all previous versions.
> >
> > Using the bwrap binary with the setuid bit set is no longer supported
> > and user namespaces are now always required, so a kernel config fixup
> > is applied.
> >
> > A new build option allows indicating the minimum kernel version that
> > will be used, which removes code used for backwards compatibility with
> > kernels older than 5.6.0 when a newer version is specified. Passing
> > $(LINUX_VERSION_PROBED) seems reasonable here.
> >
> > This version also changed the license from LGPL-2.0+ to LGPL-2.1+,
> > hence the updated hash.
> >
> > Release notes:
> >
> > https://github.com/containers/bubblewrap/releases/tag/v0.12.0
> >
> > Signed-off-by: Adrian Perez de Castro <aperez@igalia.com>
>
> Applied to master, thanks. For info, I fixed the linux config fixup (no
> pun intended). The "_LINUX" was missing and the fixup was not applied.
> See:
> https://gitlab.com/buildroot.org/buildroot/-/commit/4cb6193d2eca39b1bd79ff4867c842f507f692b8
Good catch, thanks!
—Adrián
[-- Attachment #1.2: signature.asc --]
[-- Type: application/pgp-signature, Size: 195 bytes --]
[-- Attachment #2: Type: text/plain, Size: 150 bytes --]
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [Buildroot] [PATCH] package/bubblewrap: security bump to version 0.12.0
2026-09-10 9:52 [Buildroot] [PATCH] package/bubblewrap: security bump to version 0.12.0 Adrian Perez de Castro
2026-09-10 20:01 ` Julien Olivain via buildroot
@ 2026-09-11 13:32 ` Peter Korsgaard
2026-09-13 21:14 ` Adrian Perez de Castro
1 sibling, 1 reply; 5+ messages in thread
From: Peter Korsgaard @ 2026-09-11 13:32 UTC (permalink / raw)
To: Adrian Perez de Castro; +Cc: buildroot
>>>>> "Adrian" == Adrian Perez de Castro <aperez@igalia.com> writes:
> Fixes a sandbox escape through symlink traversal tracked in
> CVE-2026-87766, which affects all previous versions.
> Using the bwrap binary with the setuid bit set is no longer supported
> and user namespaces are now always required, so a kernel config fixup
> is applied.
> A new build option allows indicating the minimum kernel version that
> will be used, which removes code used for backwards compatibility with
> kernels older than 5.6.0 when a newer version is specified. Passing
> $(LINUX_VERSION_PROBED) seems reasonable here.
> This version also changed the license from LGPL-2.0+ to LGPL-2.1+,
> hence the updated hash.
> Release notes:
> https://github.com/containers/bubblewrap/releases/tag/v0.12.0
> Signed-off-by: Adrian Perez de Castro <aperez@igalia.com>
> ---
> package/bubblewrap/bubblewrap.hash | 6 +++---
> package/bubblewrap/bubblewrap.mk | 17 +++++++----------
> 2 files changed, 10 insertions(+), 13 deletions(-)
> diff --git a/package/bubblewrap/bubblewrap.hash b/package/bubblewrap/bubblewrap.hash
> index e87d3c81cb..e150e1495d 100644
> --- a/package/bubblewrap/bubblewrap.hash
> +++ b/package/bubblewrap/bubblewrap.hash
> @@ -1,5 +1,5 @@
> -# From https://github.com/containers/bubblewrap/releases/download/v0.11.2/bubblewrap-0.11.2.tar.xz.sha256sum
> -sha256 69abc30005d2186baf7737feacd8da35633b93cf5af38838ecff17c5f8e924f6 bubblewrap-0.11.2.tar.xz
> +# From https://github.com/containers/bubblewrap/releases/download/v0.12.0/bubblewrap-0.12.0.tar.xz.sha256sum
> +sha256 9760d007363e3abba7c747489910f9f82d9fca53ba3bd3282e396fa3c97a3314 bubblewrap-0.12.0.tar.xz
> # Hash for license files:
> -sha256 b7993225104d90ddd8024fd838faf300bea5e83d91203eab98e29512acebd69c COPYING
> +sha256 dc626520dcd53a22f727af3ee42c770e56c97a64fe3adb063799d8ab032fe551 COPYING
> diff --git a/package/bubblewrap/bubblewrap.mk b/package/bubblewrap/bubblewrap.mk
> index 7838ab90b3..40a8148e14 100644
> --- a/package/bubblewrap/bubblewrap.mk
> +++ b/package/bubblewrap/bubblewrap.mk
> @@ -4,21 +4,24 @@
> #
> ################################################################################
> -BUBBLEWRAP_VERSION = 0.11.2
> +BUBBLEWRAP_VERSION = 0.12.0
> BUBBLEWRAP_SITE = https://github.com/containers/bubblewrap/releases/download/v$(BUBBLEWRAP_VERSION)
> BUBBLEWRAP_SOURCE = bubblewrap-$(BUBBLEWRAP_VERSION).tar.xz
> BUBBLEWRAP_DEPENDENCIES = host-pkgconf libcap
> -BUBBLEWRAP_LICENSE = LGPL-2.0+
> +BUBBLEWRAP_LICENSE = LGPL-2.1+
> BUBBLEWRAP_LICENSE_FILES = COPYING
> BUBBLEWRAP_CPE_ID_VENDOR = projectatomic
> +define BUBBLEWRAP_CONFIG_FIXUPS
> + $(call KCONFIG_ENABLE_OPT,CONFIG_USER_NS)
> +endef
> +
> BUBBLEWRAP_CONF_OPTS = \
> + -Dassume_kernel=$(LINUX_VERSION_PROBED) \
What happens if the config does not build a Linux kernel (then this
presumably expands to -Dassume_kernel=)?
--
Bye, Peter Korsgaard
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [Buildroot] [PATCH] package/bubblewrap: security bump to version 0.12.0
2026-09-11 13:32 ` Peter Korsgaard
@ 2026-09-13 21:14 ` Adrian Perez de Castro
0 siblings, 0 replies; 5+ messages in thread
From: Adrian Perez de Castro @ 2026-09-13 21:14 UTC (permalink / raw)
To: Peter Korsgaard; +Cc: buildroot
[-- Attachment #1.1: Type: text/plain, Size: 3475 bytes --]
Hello Peter,
On Fri, 11 Sep 2026 15:32:48 +0200 Peter Korsgaard <peter@korsgaard.com> wrote:
> >>>>> "Adrian" == Adrian Perez de Castro <aperez@igalia.com> writes:
>
> > Fixes a sandbox escape through symlink traversal tracked in
> > CVE-2026-87766, which affects all previous versions.
>
> > Using the bwrap binary with the setuid bit set is no longer supported
> > and user namespaces are now always required, so a kernel config fixup
> > is applied.
>
> > A new build option allows indicating the minimum kernel version that
> > will be used, which removes code used for backwards compatibility with
> > kernels older than 5.6.0 when a newer version is specified. Passing
> > $(LINUX_VERSION_PROBED) seems reasonable here.
>
> > This version also changed the license from LGPL-2.0+ to LGPL-2.1+,
> > hence the updated hash.
>
> > Release notes:
>
> > https://github.com/containers/bubblewrap/releases/tag/v0.12.0
>
> > Signed-off-by: Adrian Perez de Castro <aperez@igalia.com>
> > ---
> > package/bubblewrap/bubblewrap.hash | 6 +++---
> > package/bubblewrap/bubblewrap.mk | 17 +++++++----------
> > 2 files changed, 10 insertions(+), 13 deletions(-)
>
> > diff --git a/package/bubblewrap/bubblewrap.hash b/package/bubblewrap/bubblewrap.hash
> > index e87d3c81cb..e150e1495d 100644
> > --- a/package/bubblewrap/bubblewrap.hash
> > +++ b/package/bubblewrap/bubblewrap.hash
> > @@ -1,5 +1,5 @@
> > -# From https://github.com/containers/bubblewrap/releases/download/v0.11.2/bubblewrap-0.11.2.tar.xz.sha256sum
> > -sha256 69abc30005d2186baf7737feacd8da35633b93cf5af38838ecff17c5f8e924f6 bubblewrap-0.11.2.tar.xz
> > +# From https://github.com/containers/bubblewrap/releases/download/v0.12.0/bubblewrap-0.12.0.tar.xz.sha256sum
> > +sha256 9760d007363e3abba7c747489910f9f82d9fca53ba3bd3282e396fa3c97a3314 bubblewrap-0.12.0.tar.xz
>
> > # Hash for license files:
> > -sha256 b7993225104d90ddd8024fd838faf300bea5e83d91203eab98e29512acebd69c COPYING
> > +sha256 dc626520dcd53a22f727af3ee42c770e56c97a64fe3adb063799d8ab032fe551 COPYING
> > diff --git a/package/bubblewrap/bubblewrap.mk b/package/bubblewrap/bubblewrap.mk
> > index 7838ab90b3..40a8148e14 100644
> > --- a/package/bubblewrap/bubblewrap.mk
> > +++ b/package/bubblewrap/bubblewrap.mk
> > @@ -4,21 +4,24 @@
> > #
> > ################################################################################
>
> > -BUBBLEWRAP_VERSION = 0.11.2
> > +BUBBLEWRAP_VERSION = 0.12.0
> > BUBBLEWRAP_SITE = https://github.com/containers/bubblewrap/releases/download/v$(BUBBLEWRAP_VERSION)
> > BUBBLEWRAP_SOURCE = bubblewrap-$(BUBBLEWRAP_VERSION).tar.xz
> > BUBBLEWRAP_DEPENDENCIES = host-pkgconf libcap
>
> > -BUBBLEWRAP_LICENSE = LGPL-2.0+
> > +BUBBLEWRAP_LICENSE = LGPL-2.1+
> > BUBBLEWRAP_LICENSE_FILES = COPYING
> > BUBBLEWRAP_CPE_ID_VENDOR = projectatomic
>
> > +define BUBBLEWRAP_CONFIG_FIXUPS
> > + $(call KCONFIG_ENABLE_OPT,CONFIG_USER_NS)
> > +endef
> > +
> > BUBBLEWRAP_CONF_OPTS = \
> > + -Dassume_kernel=$(LINUX_VERSION_PROBED) \
>
> What happens if the config does not build a Linux kernel (then this
> presumably expands to -Dassume_kernel=)?
Exactly, and the empty value is the default as well for the option. In
that case the fallback code for older kernel versions is enabled for the
Bubblewrap build. IMO that is the right thing to do because we cannot
guess which kernel version will be used at runtime.
Cheers,
—Adrián
[-- Attachment #1.2: signature.asc --]
[-- Type: application/pgp-signature, Size: 195 bytes --]
[-- Attachment #2: Type: text/plain, Size: 150 bytes --]
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-09-13 21:14 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-10 9:52 [Buildroot] [PATCH] package/bubblewrap: security bump to version 0.12.0 Adrian Perez de Castro
2026-09-10 20:01 ` Julien Olivain via buildroot
2026-09-11 0:07 ` Adrian Perez de Castro
2026-09-11 13:32 ` Peter Korsgaard
2026-09-13 21:14 ` Adrian Perez de Castro
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox