USN-8779-2: Bubblewrap regression | Ubuntu security notices

USN-8779-1 fixed vulnerabilities in Bubblewrap. Unfortunately, the fix for
CVE-2026-87766 introduced a regression in symlink resolution, preventing
certain Flatpak applications from launching. This update reverts that fix
until a complete fix is available.

We apologize for the inconvenience.

Original advisory details:

It was discovered that Bubblewrap incorrectly handled certain temporary
directories. A local attacker could possibly use this issue to cause a
denial of service or execute arbitrary code. This issue only affected
Ubuntu 18.04 LTS. (CVE-2019-12439)

It was discovered that Bubblewrap incorrectly handled certain symlinks
during sandbox setup. A local attacker could possibly use this issue to
create files outside of the sandbox. (CVE-2026-87766)

USN-8779-1 fixed vulnerabilities in Bubblewrap. Unfortunately, the fix for
CVE-2026-87766 introduced a regression in symlink resolution, preventing
certain Flatpak applications from launching. This update reverts that fix
until a complete fix is available.

We apologize for the inconvenience.

Original advisory details:

It was discovered that Bubblewrap incorrectly handled certain temporary
directories. A local attacker could possibly use this issue to cause a
denial of service or execute arbitrary code. This issue only affected
Ubuntu 18.04 LTS. (CVE-2019-12439)

It was discovered that Bubblewrap incorrectly handled certain symlinks
during sandbox setup. A local attacker could possibly use this issue to
create files outside of the sandbox. (CVE-2026-87766)

Scroll to Top