cbcvebase.
CVE-2020-5291
published 2020-03-31

CVE-2020-5291: Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2` option…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.91%
56.1th percentile
Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2` option can be used to make the setuid process keep running as root while being traceable. This can in turn be used to gain root permissions. Note that this only affects the combination of bubblewrap in setuid mode (which is typically used when unprivileged user namespaces are not supported) and the support of unprivileged user namespaces. Known to be affected are: * Debian testing/unstable, if unprivileged user namespaces enabled (not default) * Debian buster-backports, if unprivileged user namespaces enabled (not default) * Arch if using `linux-hardened`, if unprivileged user namespaces enabled (not default) * Centos 7 flatpak COPR, if unprivileged user namespaces enabled (not default) This has been fixed in the 0.4.1 release, and all affected users should update.

Affected

12 ranges
VendorProductVersion rangeFixed in
centoscentos
containersbubblewrap< 0.4.10.4.1
containersbubblewrap>= 0 < 0.4.1-10.4.1-1
containersbubblewrap>= 0 < 0.4.1-10.4.1-1
containersbubblewrap>= 0 < 0.4.1-10.4.1-1
containersbubblewrap>= 0 < 0.4.1-10.4.1-1
debianbubblewrap< bubblewrap 0.4.1-1 (bookworm)bubblewrap 0.4.1-1 (bookworm)
debiandebian_linux
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_bubblewrap_0.3.0-5_on_cbl_mariner_1.0
projectatomicbubblewrap< 0.4.10.4.1

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.08.5HIGHAV:N/AC:M/Au:S/C:C/I:C/A:C
osv7.8HIGH
vendor_msrc7.8HIGH
vendor_debian7.2LOW
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.