Skip to content
Release 0.1.6 (CVE-2017-5226)

This fixes a security issue with `TIOCSTI`, aka CVE-2017-522. Note bubblewrap is
far from the only program that has this issue, and I think the best fix is
probably in the kernel to support disabling this ioctl.

Programs can also work around this by calling `setsid()` on their own in an exec
handler before doing an `exevp("bwrap")`.

Git-EVTag-v0-SHA512: aea2bc21fa6194f7d5c4eaf7294dd35e4434616678d2f79c1e9044aca063bf77db199b1030628ced2eb7d3a33d6a6419047e32ea7891be396d9ddb50a7b1f745