QID 198670

Date Published: 2022-02-21

QID 198670: Ubuntu Security Notification for snapd Vulnerabilities (USN-5292-2)

Snap did not properly manage the permissions for the snap directories.
Snapd did not properly validate content interfaces and layout paths.
Snapd did not properly validate the location of the snap-confine binary.
A race condition existed in the snapd snap-confine binary when preparing a private mount namespace for a snap.

Usn-5292-1 fixed vulnerabilities in snapd.
This update provides thecorresponding update for the riscv64 architecture.
A local attacker could possibly use this issue to expose sensitive information.
A local attacker could possibly use this issue to inject arbitrary apparmor policy rules, resulting in a bypass of intended access restrictions.
A local attacker could possibly use this issue to execute other arbitrary binaries and escalate privileges.
A local attacker could possibly use this issue to escalate privileges and execute arbitrary code.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.9 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5292-2 for updates and patch information.
    Vendor References

    CVEs related to QID 198670

    Software Advisories
    Advisory ID Software Component Link
    USN-5292-2 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5292-2