CVE-2026-41163
published 2026-05-09CVE-2026-41163: bubblewrap is a low-level unprivileged sandboxing tool. From version 0.11.0 to before version 0.11.2, if bubblewrap is installed in setuid mode then the user…
PriorityP336high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.27%
19.6th percentile
bubblewrap is a low-level unprivileged sandboxing tool. From version 0.11.0 to before version 0.11.2, if bubblewrap is installed in setuid mode then the user can use ptrace to attach to bubblewrap and control the unprivileged part of the sandbox setup phase. This allows the attacker to arbitrarily use the privileged operations, and in particular the "overlay mount" operation, allowing the creation of overlay mounts which is otherwise not allowed in the setuid version of bubblewrap. This issue has been patched in version 0.11.2.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| containers | bubblewrap | — | — |
| ubuntu | bubblewrap | — | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat8.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
containers bubblewrap 0.11.0/0.11.1 ptrace access control
vuldb·2026-04-25
CVE-2026-41163 [CRITICAL] containers bubblewrap 0.11.0/0.11.1 ptrace access control
A vulnerability was found in containers bubblewrap 0.11.0/0.11.1. It has been declared as critical. Affected by this issue is some unknown functionality of the component ptrace. Such manipulation leads to improper access controls.
This vulnerability is traded as CVE-2026-41163. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
Ubuntu
Bubblewrap vulnerability
vendor_ubuntu·2026-05-20
CVE-2026-41163 Bubblewrap vulnerability
Title: Bubblewrap vulnerability
Summary: Bubblewrap could be made to bypass sandbox restrictions.
It was discovered that Bubblewrap incorrectly handled the sandbox
setup phase when installed in setuid mode. A local attacker could
possibly use this issue to bypass sandbox restrictions.
Instructions: In general, a standard system update will make all the necessary
changes.
Red Hat
bubblewrap: bubblewrap: Privilege escalation via ptrace when installed in setuid mode
vendor_redhat·2026-05-09·CVSS 8.7
CVE-2026-41163 [HIGH] CWE-266 bubblewrap: bubblewrap: Privilege escalation via ptrace when installed in setuid mode
bubblewrap: bubblewrap: Privilege escalation via ptrace when installed in setuid mode
A flaw was found in bubblewrap when operating in setuid mode. A local user may use ptrace to interfere with the sandbox setup process and gain access to privileged operations that are normally restricted. This could allow an attacker to bypass intended sandboxing restrictions and potentially elevate privileges on the system.
Statement: This vulnerability affects bubblewrap's setuid mode. During sandbox initialization, insufficient isolation between privileged and unprivileged processing stages allows a local attacker to manipulate the sandbox setup process using ptrace.
```
The vulnerability relies on support for overlay filesystem mounts. The overlayfs mount support was added in bubblewrap version 0.11
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-41163 bubblewrap: bubblewrap: Privilege escalation via ptrace when installed in setuid mode [fedora-all]
bugzilla·2026-06-01·CVSS 8.7
CVE-2026-41163 [HIGH] CVE-2026-41163 bubblewrap: bubblewrap: Privilege escalation via ptrace when installed in setuid mode [fedora-all]
CVE-2026-41163 bubblewrap: bubblewrap: Privilege escalation via ptrace when installed in setuid mode [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This CVE (ie., CVE-2026-41163) only affects bubblewrap binaries (ie., /usr/bin/bwrap) that have the setuid bit set:
https://github.com/containers/bubblewrap/releases/tag/v0.11.2
https://github.com/containers/bubblewrap/security/advisories/GHSA-xq78-7hw4-5jvp
Fedora has never used those.
Bugzilla
CVE-2026-41163 bubblewrap: bubblewrap: Privilege escalation via ptrace when installed in setuid mode
bugzilla·2026-05-09·CVSS 8.7
CVE-2026-41163 [HIGH] CVE-2026-41163 bubblewrap: bubblewrap: Privilege escalation via ptrace when installed in setuid mode
CVE-2026-41163 bubblewrap: bubblewrap: Privilege escalation via ptrace when installed in setuid mode
bubblewrap is a low-level unprivileged sandboxing tool. From version 0.11.0 to before version 0.11.2, if bubblewrap is installed in setuid mode then the user can use ptrace to attach to bubblewrap and control the unprivileged part of the sandbox setup phase. This allows the attacker to arbitrarily use the privileged operations, and in particular the "overlay mount" operation, allowing the creation of overlay mounts which is otherwise not allowed in the setuid version of bubblewrap. This issue has been patched in version 0.11.2.
https://github.com/containers/bubblewrap/releases/tag/v0.11.2https://github.com/containers/bubblewrap/security/advisories/GHSA-xq78-7hw4-5jvphttps://access.redhat.com/security/cve/CVE-2026-41163https://bugzilla.redhat.com/show_bug.cgi?id=2468439https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41163.json
2026-05-09
Published