Format: 1.8
Date: Wed, 26 Aug 2026 12:40:33 +0100
Binary: bubblewrap bubblewrap-dbgsym
Source: bubblewrap
Architecture: amd64 source
Version: 0.12.0-1~deb13u1~1+20+gda0b399
Distribution: UNRELEASED
Urgency: high
Maintainer: Utopia Maintenance Team <pkg-utopia-maintainers@lists.alioth.debian.org>
Changed-By: Snapshot <snapshot@localhost>
Closes: 1145655
Description: 
 bubblewrap - utility for unprivileged chroot and namespace manipulation
Changes:
 bubblewrap (0.12.0-1~deb13u1~1+20+gda0b399) UNRELEASED; urgency=medium
 .
   * Snapshot build (local package)
 .
   * snapshot: commit da0b399 (20 commits after 0.12.0-1)
 .
 bubblewrap (0.12.0-1~deb13u1) trixie-security; urgency=high
 .
   * Merge new upstream release from unstable
     - Prevent sandbox escape via symlink traversal.
       If an app framework such as Flatpak mounts subdirectories into a
       directory controlled by the sandboxed app, a malicious or compromised
       sandboxed app could create symlinks in that directory to arrange for
       files/directories to be created on the host system.
       (GHSA-pxhw-h44j-8pfx, no known CVE ID; Closes: #1145655)
     - bubblewrap no longer supports running when setuid, matching the
       upstream default. This ensures that vulnerabilities similar to
       CVE-2026-41163 can't happen in future.
   * Debian 13 backport changes:
     - d/control, d/gbp.conf: Branch for Debian 13 stable updates
     - Revert packaging changes that are not appropriate for a stable release
   * Packaging changes since 0.11.0-2+deb13u1:
     - d/rules: Stop passing -Dsupport_setuid=false.
       The option no longer exists, and the new version of bubblewrap always
       behaves as though its value was false.
     - d/rules: Don't compile fallback code paths for kernel older than 5.10.
       This ensures that we're using the safest available mechanisms,
       using the openat2() syscall rather than emulating it in user-space.
       As a result, this version will not work on kernels older than the
       one found in Debian 11.
     - d/rules: Install NEWS.md as the upstream changelog
     - d/p/CVE-2026-41163/:
       Drop patches, no longer needed/applicable with the new upstream release
     - d/p/debian/Change-EPERM-error-message-to-show-Debian-specific-inform.patch:
       Adjust patch to apply to the new upstream release
     - d/README.Debian: Rewrite to reflect that setuid is no longer supported
     - d/copyright: Update license from LGPL-2+ to LGPL-2.1+, matching upstream
 .
 bubblewrap (0.12.0-1) unstable; urgency=high
 .
   * New upstream release
     - Prevent sandbox escape via symlink traversal.
       If an app framework such as Flatpak mounts subdirectories into a
       directory controlled by the sandboxed app, a malicious or compromised
       sandboxed app could create symlinks in that directory to arrange for
       files/directories to be created on the host system.
       (GHSA-pxhw-h44j-8pfx, no known CVE ID; Closes: #1145655)
     - d/rules: Stop passing -Dsupport_setuid=false.
       The option no longer exists, and the new version of bubblewrap always
       behaves as though its value was false.
     - d/copyright: Update license from LGPL-2+ to LGPL-2.1+, matching upstream
     - d/p/debian/Change-EPERM-error-message-to-show-Debian-specific-inform.patch:
       Adjust patch to apply to the new upstream release
   * d/rules: Don't compile fallback code paths for kernel older than 5.10.
     This ensures that we're using the safest available mechanisms,
     using the openat2() syscall rather than emulating it in user-space.
     As a result, this version will not work on kernels older than the
     one found in Debian 11.
 .
 bubblewrap (0.11.2-2) unstable; urgency=medium
 .
   * d/rules: Stop allowing bubblewrap to run when setuid, matching
     the upstream default. This ensures that vulnerabilities similar to
     CVE-2026-41163 can't happen in future.
   * d/control, d/NEWS, d/README.Debian: Update documentation accordingly
   * Standards-Version: 4.7.4 (no changes required)
Checksums-Sha1: 
 7dac708bd34483aa95a8b0b388f670b835862350 1535 bubblewrap_0.12.0-1~deb13u1~1+20+gda0b399.dsc
 183eaff6b078c1ea5ad55271e7d1fa5c8c0d339e 126452 bubblewrap_0.12.0.orig.tar.xz
 1073ad09dde585b201e1cc06986a7300141487fd 13816 bubblewrap_0.12.0-1~deb13u1~1+20+gda0b399.debian.tar.xz
 c9a4d5578e95ab19ef941c9b86369ef4ff8fddcf 6721 bubblewrap_0.12.0-1~deb13u1~1+20+gda0b399_source.buildinfo
 98b4b70feb500a6a62442f4d398bf2847a8053b5 92664 bubblewrap-dbgsym_0.12.0-1~deb13u1~1+20+gda0b399_amd64.deb
 101cd2e9df6218d9b622b8f9c03ed6cd5c3c0bdd 7115 bubblewrap_0.12.0-1~deb13u1~1+20+gda0b399_amd64.buildinfo
 f8d4dcb94ef61064dcb10af20198f4c862816b49 56964 bubblewrap_0.12.0-1~deb13u1~1+20+gda0b399_amd64.deb
Checksums-Sha256: 
 b88ff8d8e353ef8477500eb11e8958f9cadaa5b75551f55c1720717006da6eb4 1535 bubblewrap_0.12.0-1~deb13u1~1+20+gda0b399.dsc
 9760d007363e3abba7c747489910f9f82d9fca53ba3bd3282e396fa3c97a3314 126452 bubblewrap_0.12.0.orig.tar.xz
 c2348739a6d93f5b4f47bd22c883fbb3d591a52ade121032563b3e756a962951 13816 bubblewrap_0.12.0-1~deb13u1~1+20+gda0b399.debian.tar.xz
 668f06d30ba9516a01358bbea6327a14a52dc41e4c13163ffd546b1682eab9bc 6721 bubblewrap_0.12.0-1~deb13u1~1+20+gda0b399_source.buildinfo
 d0a53fc9beea62c67a8b570a6610ee02f546949112b88bc27ab7706c122805c8 92664 bubblewrap-dbgsym_0.12.0-1~deb13u1~1+20+gda0b399_amd64.deb
 6525a279911ad22acf92263500981cbb97ad0a985383e748908da718a24f341a 7115 bubblewrap_0.12.0-1~deb13u1~1+20+gda0b399_amd64.buildinfo
 5e4fb634f4faaf5cce04bb557b68889d86dc170e4bcdf8de5f8efa18f5d0339e 56964 bubblewrap_0.12.0-1~deb13u1~1+20+gda0b399_amd64.deb
Files: 
 6d0a85b472b07b8f9309d8c70a27d71c 1535 admin optional bubblewrap_0.12.0-1~deb13u1~1+20+gda0b399.dsc
 323b059c9599b60b456bcf9e9800ff44 126452 admin optional bubblewrap_0.12.0.orig.tar.xz
 74d271e4b1228e1bbb45b96a7f4594be 13816 admin optional bubblewrap_0.12.0-1~deb13u1~1+20+gda0b399.debian.tar.xz
 a0c3561be3d297c13f0c067922675b8d 6721 admin optional bubblewrap_0.12.0-1~deb13u1~1+20+gda0b399_source.buildinfo
 efa8c92a0de0d00d58d3f065a0e7f1af 92664 debug optional bubblewrap-dbgsym_0.12.0-1~deb13u1~1+20+gda0b399_amd64.deb
 4401148494d4e2589682f36c557c339f 7115 admin optional bubblewrap_0.12.0-1~deb13u1~1+20+gda0b399_amd64.buildinfo
 319b4919c1b601994791b83214cd9c63 56964 admin optional bubblewrap_0.12.0-1~deb13u1~1+20+gda0b399_amd64.deb
