VendorsCanonicalsnapdany version
Vulnerabilities

Canonical Snapd any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2019-7304
Local privilege escalation via snapd socket
Published 2019-04-23 · Modified
10.02 PoCEPSS 0.608
CVE-2023-1523
Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause arbitrary commands to be executed outside of the snap sandbox after the snap exits. Graphical terminal emulators like xterm, gnome-terminal and others are not affected - this can only be exploited when snaps are run on a virtual console.
Published 2023-09-01 · Modified
10.0EPSS 0.014
CVE-2020-27352
When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd will move processes from the containers created and managed by these snaps into the cgroup of the main daemon within the snap itself when reloading system units. This may grant additional privileges to a container within the snap that were not originally intended.
Published 2024-06-21 · Analyzed
9.3EPSS 0.003
CVE-2021-44730
snapd could be made to escalate privileges and run programs as administrator
Published 2022-02-17 · Modified
8.8EPSS 0.004
CVE-2021-4120
snapd could be made to bypass intended access restrictions through snap content interfaces and layout paths
Published 2022-02-17 · Modified
8.2EPSS 0.004
CVE-2024-1724
snapd allows $HOME/bin symlink
Published 2024-07-25 · Modified
8.2EPSS 0.003
CVE-2024-5138
The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. It was found that snapctl did not properly parse command-line arguments, allowing an unprivileged user to trigger an authorised action on behalf of the snap that would normally require administrator privileges to perform. This could possibly allow an unprivileged user to perform a denial of service or similar.
Published 2024-05-31 · Analyzed
8.1EPSS 0.008
CVE-2021-44731
snapd could be made to escalate privileges and run programs as administrator
Published 2022-02-17 · Modified
7.8EPSS 0.010
CVE-2022-3328
Race condition in snap-confine's must_mkdir_and_open_with_perms()
Published 2024-01-08 · Modified
7.8EPSS 0.004
CVE-2019-7303
Snapd seccomp filter TIOCSTI ioctl bypass
Published 2019-04-23 · Modified
7.51 PoCEPSS 0.037
CVE-2019-11502
snap-confine in snapd before 2.38 incorrectly set the ownership of a snap application to the uid and gid of the first calling user. Consequently, that user had unintended access to a private /tmp directory.
Published 2019-04-24 · Modified
7.5EPSS 0.025
CVE-2019-11503
snap-confine as included in snapd before 2.39 did not guard against symlink races when performing the chdir() to the current working directory of the calling user, aka a "cwd restore permission bypass."
Published 2019-04-24 · Modified
7.5EPSS 0.024
CVE-2024-29069
snapd will follow archived symlinks when unpacking a filesystem
Published 2024-07-25 · Modified
7.3EPSS 0.002
CVE-2020-11933
local snapd exploit through cloud-init
Published 2020-07-29 · Modified
7.3EPSS 0.002
CVE-2024-29068
snapd non-regular file indefinite blocking read
Published 2024-07-25 · Modified
6.6EPSS 0.002
CVE-2021-3155
snapd created ~/snap with too-wide permissions
Published 2022-02-17 · Modified
5.5EPSS 0.003