You should report this to Ubuntu OpenID transaction in progress. The last command makes the bubblewrap binary SUID, by default it is supposed to work with unprivileged user namespaces.
This is most likely due to Ubuntu doing some kernel and apparmor related changes that landed in 24.04.