bubblewrap escape via TIOCSTI ioctl
Bug #1657357 reported by
Jeremy Bícha
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
bubblewrap (Debian) |
Fix Released
|
Unknown
|
|||
bubblewrap (Ubuntu) |
Fix Released
|
Medium
|
Unassigned | ||
flatpak (Ubuntu) |
Fix Released
|
Medium
|
Unassigned |
Bug Description
Another bubblewrap security issue for yakkety. Changelogs are derived from Debian's. This has already been fixed in Debian and zesty.
This has been fixed in Debian and upstream in both bubblewrap and Flatpak which need to be updated at the same time.
For Flatpak, this is just backporting
https:/
For bubblewrap, there's only a few other bugfixes added in the new upstream version 0.1.7 since 0.1.5 so I think we'd be better off just taking the new version:
https:/
https:/
Originally, I mixed this bug with LP: #1656712 but it's a lot simpler now.
CVE References
information type: | Public → Public Security |
Changed in bubblewrap (Ubuntu): | |
importance: | Undecided → Medium |
Changed in flatpak (Ubuntu): | |
importance: | Undecided → Medium |
Changed in bubblewrap (Debian): | |
status: | Unknown → Fix Released |
description: | updated |
Changed in bubblewrap (Ubuntu): | |
status: | New → Confirmed |
Changed in flatpak (Ubuntu): | |
status: | New → Confirmed |
To post a comment you must log in.
I noticed the changelog links to the wrong bug in the flatpak and bubblewrap debdiffs.
It links to an older security bug not this one.