CVE-2016-8659: Bubblewrap Project Bubblewrap
High severity, CVSS 7.0. EPSS: 0.4% chance of exploitation in the next 30 days.
Bubblewrap before 0.1.3 sets the PR_SET_DUMPABLE flag, which might allow local users to gain privileges by attaching to the process, as demonstrated by sending commands to a PrivSep socket.
Affected products
- Bubblewrap Project Bubblewrap: up to and including 0.1.1
Published 2017-02-13. Last modified 2026-06-17.