Back

HIGH

bubblewrap: temporary directory misuse as mount point

Published May 29, 2019

Description

bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in /tmp as a mount point. In some particular configurations (related to XDG_RUNTIME_DIR), a local attacker may abuse this flaw to prevent other users from executing bubblewrap or potentially execute code.

Affected products

Remediation

Red Hat statement

This flaw requires a local user account to exploit. Since local users without root privileges are not supported on Red Had CloudForms, or on Red Hat Ansible Tower, this vulnerability is rated Low severity on these products. Future updates may address this vulnerability.

Red Hat mitigation

The default setting of `fs.protected_symlinks = 1` prevents any Confidentiality or Integrity impact from exploiting this vulnerability, reducing its rating to Low severity (4.7/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 29, 2019
Updated Aug 4, 2024
Reserved May 29, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 1, 2019