CVE-2021-4120
Summary
| CVE | CVE-2021-4120 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-17 23:15:00 UTC |
| Updated | 2023-11-07 03:40:00 UTC |
| Description | snapd 2.54.2 fails to perform sufficient validation of snap content interface and layout paths, resulting in the ability for snaps to inject arbitrary AppArmor policy rules via malformed content interface and layout declarations and hence escape strict snap confinement. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1 |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 35 Update: snapd-2.54.3-1.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Bug #1949368 “snapd fails to validate content interface settings...” : Bugs : snapd |
MISC |
bugs.launchpad.net |
|
| [SECURITY] Fedora 34 Update: snapd-2.54.3-1.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| USN-5292-1: snapd vulnerabilities | Ubuntu security notices | Ubuntu |
MISC |
ubuntu.com |
|
| [SECURITY] Fedora 34 Update: snapd-2.54.3-1.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| oss-security - CVE-2021-4120: Insufficient validation of snap content interface
and layout paths |
MLIST |
www.openwall.com |
|
| [SECURITY] Fedora 35 Update: snapd-2.54.3-1.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Ian Johnson
Legacy QID Mappings
- 180453 Debian Security Update for snapd (CVE-2021-4120)
- 198668 Ubuntu Security Notification for snapd Vulnerabilities (USN-5292-1)
- 198670 Ubuntu Security Notification for snapd Vulnerabilities (USN-5292-2)
- 282412 Fedora Security Update for snapd (FEDORA-2022-5df8b52ba4)
- 282413 Fedora Security Update for snapd (FEDORA-2022-82bea71e5a)