QID 198668

Date Published: 2022-02-21

QID 198668: Ubuntu Security Notification for snapd Vulnerabilities (USN-5292-1)

Snap did not properly manage the permissions forthe snap directories.
Snapd did not properly validate content interfacesand layout paths.
Snapd did not properly validate thelocation of the snap-confine binary.
A race condition existed in the snapdsnap-confine binary when preparing a private mount namespace for a snap.

A local attacker could possibly use this issue to exposesensitive information.
A local attacker could possibly use this issue to injectarbitrary apparmor policy rules, resulting in a bypass of intended accessrestrictions.
A local attacker could possibly use thisissue to execute other arbitrary binaries and escalate privileges.
Alocal attacker could possibly use this issue to escalate privileges andexecute arbitrary code.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.9 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5292-1 for updates and patch information.
    Vendor References

    CVEs related to QID 198668

    Software Advisories
    Advisory ID Software Component Link
    USN-5292-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5292-1