Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
This CVE (ie., CVE-2026-41163) only affects bubblewrap binaries (ie., /usr/bin/bwrap) that have the setuid bit set: https://github.com/containers/bubblewrap/releases/tag/v0.11.2 https://github.com/containers/bubblewrap/security/advisories/GHSA-xq78-7hw4-5jvp Fedora has never used those.