When executing a program via the bubblewrap sandbox, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the sandbox.
CVSS Details
- CVSS 3.0 Base Score: 10
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade bubblewrap | Jul 30, 2024 | Mar 29, 2017 |
| Oracle Solaris | — | Upgrade library/desktop/webkitgtk4 to version 2.28.4-11.4.26.0.1.75.3 on Solaris 11.4 | Jan 19, 2021 | Mar 29, 2017 |
| Suse | — | Upgrade libflatpak0Upgrade flatpak-zsh-completionUpgrade system-user-flatpakUpgrade flatpakUpgrade flatpak-develUpgrade bubblewrapUpgrade typelib-1_0-flatpak-1_0 | May 20, 2018 | Mar 29, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub