Junglewise Threat Intelligence

CVE-2026-41163: Project Atomic bubblewrap privilege escalation in setuid mode via ptrace

CVE-2026-41163 · Severity: high · CVSS 7 · Published 2026-05-09

Vendors: Containers.

Executive brief

bubblewrap is a tool used to create secure, isolated environments (sandboxes) for running applications. A vulnerability exists when the tool is installed with special system permissions (setuid mode), allowing a local user to interfere with the setup process. This could allow an attacker to bypass security restrictions and perform unauthorized actions, such as creating restricted file system mounts, potentially leading to a full system compromise.

Technical details

A privilege escalation vulnerability exists in bubblewrap versions 0.11.0 through 0.11.1 when installed in setuid mode. The root cause is that the low-privileged portion of the sandbox setup phase is executed as 'dumpable', which allows a local attacker to attach to the process using ptrace. By hijacking this phase, an attacker can manipulate the privileged operations of the setuid binary, specifically enabling 'overlay mount' operations that are normally restricted. This allows for unauthorized file system manipulation and potential elevation of privileges. The issue is resolved in version 0.11.2 by ensuring setup code is not dumpable and deprecating setuid support.

Affected products

  • containers bubblewrap >= 0.11.0, < 0.11.2

Timeline

  • 2026-04-23: patched: Version 0.11.2 released
  • 2026-04-23: advisory: GitHub Security Advisory GHSA-xq78-7hw4-5jvp published
  • 2026-05-09: disclosed: CVE-2026-41163 published to NVD

References