CVE-2020-5291
published 2020-03-31CVE-2020-5291: Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2` option…
PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.91%
56.1th percentile
Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2` option can be used to make the setuid process keep running as root while being traceable. This can in turn be used to gain root permissions. Note that this only affects the combination of bubblewrap in setuid mode (which is typically used when unprivileged user namespaces are not supported) and the support of unprivileged user namespaces. Known to be affected are: * Debian testing/unstable, if unprivileged user namespaces enabled (not default) * Debian buster-backports, if unprivileged user namespaces enabled (not default) * Arch if using `linux-hardened`, if unprivileged user namespaces enabled (not default) * Centos 7 flatpak COPR, if unprivileged user namespaces enabled (not default) This has been fixed in the 0.4.1 release, and all affected users should update.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| centos | centos | — | — |
| containers | bubblewrap | < 0.4.1 | 0.4.1 |
| containers | bubblewrap | >= 0 < 0.4.1-1 | 0.4.1-1 |
| containers | bubblewrap | >= 0 < 0.4.1-1 | 0.4.1-1 |
| containers | bubblewrap | >= 0 < 0.4.1-1 | 0.4.1-1 |
| containers | bubblewrap | >= 0 < 0.4.1-1 | 0.4.1-1 |
| debian | bubblewrap | < bubblewrap 0.4.1-1 (bookworm) | bubblewrap 0.4.1-1 (bookworm) |
| debian | debian_linux | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_bubblewrap_0.3.0-5_on_cbl_mariner_1.0 | — | — |
| projectatomic | bubblewrap | < 0.4.1 | 0.4.1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.08.5HIGHAV:N/AC:M/Au:S/C:C/I:C/A:C
osv7.8HIGH
vendor_msrc7.8HIGH
vendor_debian7.2LOW
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
bubblewrap: privilege escalation in some kernel configurations
vendor_redhat·2020-03-31·CVSS 7.2
CVE-2020-5291 [HIGH] CWE-648 bubblewrap: privilege escalation in some kernel configurations
bubblewrap: privilege escalation in some kernel configurations
Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2` option can be used to make the setuid process keep running as root while being traceable. This can in turn be used to gain root permissions. Note that this only affects the combination of bubblewrap in setuid mode (which is typically used when unprivileged user namespaces are not supported) and the support of unprivileged user namespaces. Known to be affected are: * Debian testing/unstable, if unprivileged user namespaces enabled (not default) * Debian buster-backports, if unprivileged user namespaces enabled (not default) * Arch if using `linux-hardened`, if unprivileged user na
Microsoft
Privilege escalation in setuid mode via user namespaces in Bubblewrap
vendor_msrc·2020-03-10·CVSS 7.8
CVE-2020-5291 [HIGH] CWE-269 Privilege escalation in setuid mode via user namespaces in Bubblewrap
Privilege escalation in setuid mode via user namespaces in Bubblewrap
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Refe
Debian
CVE-2020-5291: bubblewrap - Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the ker...
vendor_debian·2020·CVSS 7.2
CVE-2020-5291 [HIGH] CVE-2020-5291: bubblewrap - Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the ker...
Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2` option can be used to make the setuid process keep running as root while being traceable. This can in turn be used to gain root permissions. Note that this only affects the combination of bubblewrap in setuid mode (which is typically used when unprivileged user namespaces are not supported) and the support of unprivileged user namespaces. Known to be affected are: * Debian testing/unstable, if unprivileged user namespaces enabled (not default) * Debian buster-backports, if unprivileged user namespaces enabled (not default) * Arch if using `linux-hardened`, if unprivileged user namespaces enabled (not default) * Centos 7 flatpak COPR, if unpri
OSV
CVE-2020-5291: Bubblewrap (bwrap) before version 0
osv·2020-03-31·CVSS 7.8
CVE-2020-5291 [HIGH] CVE-2020-5291: Bubblewrap (bwrap) before version 0
Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2` option can be used to make the setuid process keep running as root while being traceable. This can in turn be used to gain root permissions. Note that this only affects the combination of bubblewrap in setuid mode (which is typically used when unprivileged user namespaces are not supported) and the support of unprivileged user namespaces. Known to be affected are: * Debian testing/unstable, if unprivileged user namespaces enabled (not default) * Debian buster-backports, if unprivileged user namespaces enabled (not default) * Arch if using `linux-hardened`, if unprivileged user namespaces enabled (not default) * Centos 7 flatpak COPR, if unpri
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-5291 bubblewrap: privilege escalation in some kernel configurations [epel-7]
bugzilla·2020-04-13·CVSS 7.2
CVE-2020-5291 [HIGH] CVE-2020-5291 bubblewrap: privilege escalation in some kernel configurations [epel-7]
CVE-2020-5291 bubblewrap: privilege escalation in some kernel configurations [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for t
Bugzilla
CVE-2020-5291 bubblewrap: privilege escalation in some kernel configurations [fedora-all]
bugzilla·2020-04-13·CVSS 7.2
CVE-2020-5291 [HIGH] CVE-2020-5291 bubblewrap: privilege escalation in some kernel configurations [fedora-all]
CVE-2020-5291 bubblewrap: privilege escalation in some kernel configurations [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppor
Bugzilla
CVE-2020-5291 bubblewrap: privilege escalation in some kernel configurations
bugzilla·2020-04-13·CVSS 7.2
CVE-2020-5291 [HIGH] CVE-2020-5291 bubblewrap: privilege escalation in some kernel configurations
CVE-2020-5291 bubblewrap: privilege escalation in some kernel configurations
Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2` option can be used to make the setuid process keep running as root while being traceable. This can in turn be used to gain root permissions. Note that this only affects the combination of bubblewrap in setuid mode (which is typically used when unprivileged user namespaces are not supported) and the support of unprivileged user namespaces. Known to be affected are: * Debian testing/unstable, if unprivileged user namespaces enabled (not default) * Debian buster-backports, if unprivileged user namespaces enabled (not default) * Arch if using `linux-hardened`, if unpriv
https://github.com/containers/bubblewrap/commit/1f7e2ad948c051054b683461885a0215f1806240https://github.com/containers/bubblewrap/security/advisories/GHSA-j2qp-rvxj-43vjhttps://github.com/containers/bubblewrap/commit/1f7e2ad948c051054b683461885a0215f1806240https://github.com/containers/bubblewrap/security/advisories/GHSA-j2qp-rvxj-43vj
2020-03-31
Published