PatchSiren

Bubblewrap Project CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Bubblewrap Project CVE published 2017-02-13

CVE-2016-8659

CVE-2016-8659 describes a Bubblewrap flaw where PR_SET_DUMPABLE is set in a way that may let local users attach to the process and potentially gain privileges. The supplied NVD record rates the issue High with a local attack vector and lists affected versions through 0.1.1, while the CVE description says the problem affects Bubblewrap before 0.1.3. Treat this as a local privilege-escalation exposure affec [truncated]