bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in /tmp as a mount point. In some particular configurations (related to XDG_RUNTIME_DIR), a local attacker may abuse this flaw to prevent other users from executing bubblewrap or potentially execute code.
CVSS Details
- CVSS 3.1 Base Score: 7.4
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | debian-upgrade-bubblewrap | Jul 30, 2024 | May 29, 2019 | |
| Gentoo Linux | gentoo-linux-upgrade-sys-apps-bubblewrap | Jun 16, 2020 | May 29, 2019 | |
| Huawei Euleros 2_0_sp3 | huawei-euleros-2_0_sp3-upgrade-bubblewrap | Sep 25, 2019 | May 29, 2019 | |
| Huawei Euleros 2_0_sp8 | huawei-euleros-2_0_sp8-upgrade-bubblewrap | Jul 26, 2019 | May 29, 2019 | |
| Redhat_linux | — | no-fix-redhat-rpm-package | Jul 9, 2025 | May 29, 2019 |
| Suse | — | suse-upgrade-bubblewrap | Jun 10, 2019 | May 29, 2019 |
| Ubuntu | no-fix-ubuntu-package | Jun 26, 2025 | May 29, 2019 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | May 29, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub