https://seclists.org/oss-sec/2026/q2/215: bubblewrap CVE-2026-41163: Privilege escalation if setuid root, via ptrace
Published Apr 25, 2026
·Updated
Affected Software
1 affected component
containers bubblewrap>=0.11.0<0.11.2
Frequently Asked Questions
1
What is the severity of CVE-2026-41163?
CVE-2026-41163 is classified as a high severity privilege escalation vulnerability.
2
How do I fix CVE-2026-41163?
To fix CVE-2026-41163, upgrade bubblewrap to version 0.11.2 or later.
3
Which versions of bubblewrap are vulnerable to CVE-2026-41163?
Bubblewrap versions 0.11.0 and above that are installed with setuid root are vulnerable to CVE-2026-41163.
4
Is bubblewrap version prior to 0.11.0 affected by CVE-2026-41163?
No, bubblewrap versions prior to 0.11.0 are not believed to be vulnerable to CVE-2026-41163.
5
What type of vulnerability is CVE-2026-41163?
CVE-2026-41163 is a privilege escalation vulnerability that can be exploited via the ptrace system call.