High severity7.0NVD Advisory· Published Feb 13, 2017· Updated May 13, 2026
CVE-2016-8659
CVE-2016-8659
Description
Bubblewrap before 0.1.3 sets the PR_SET_DUMPABLE flag, which might allow local users to gain privileges by attaching to the process, as demonstrated by sending commands to a PrivSep socket.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.openwall.com/lists/oss-security/2016/10/13/4nvdMailing ListPatchThird Party Advisory
- github.com/projectatomic/bubblewrap/issues/107nvdIssue TrackingPatchThird Party Advisory
- www.openwall.com/lists/oss-security/2016/10/12/5nvdMailing ListThird Party Advisory
- www.securityfocus.com/bid/93542nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.