PT-2020-5190 · Project Atomic+1 · Bubblewrap+1
Alexlarsson
·
Published
2020-03-31
·
Updated
2024-06-15
·
CVE-2020-5291
CVSS v2.0
8.5
High
| Vector | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Bubblewrap versions prior to 0.4.1
Description
The issue is related to insecure privilege management in the Bubblewrap application. Exploitation of this issue may allow a remote attacker to impact the confidentiality and integrity of protected information. The vulnerability can be exploited when Bubblewrap is installed in setuid mode and the kernel supports unprivileged user namespaces, allowing an attacker to use the
bwrap --userns2 option to gain root permissions. This issue is known to affect certain configurations of Debian, Arch, and Centos systems where unprivileged user namespaces are enabled.Recommendations
For Bubblewrap versions prior to 0.4.1, update to version 0.4.1 or later to resolve the issue. As a temporary workaround, consider disabling the setuid mode for Bubblewrap until the update is applied. Additionally, restrict the use of the
bwrap --userns2 option to minimize the risk of exploitation.Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Bubblewrap