bubblewrap 中发现了一个缺陷。在沙箱初始化阶段,在新根目录(new root)下创建文件或目录时,可能会通过 跟随指向宿主机的父级符号链接,从而以启动用户的身份将攻击者指定的路径写入沙箱外部。该问题发生在沙箱化进程启动之前。此问题对应 GitHub 安全公告编号 GHSA-pxhw-h44j-8pfx,已在 bubblewrap 0.12.0 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Hardened Images | - |
cpe:/a:redhat:hummingbird:1
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet