CVE-2019-7303
published 2019-04-23CVE-2019-7303: A vulnerability in the seccomp filters of Canonical snapd before version 2.37.4 allows a strict mode snap to insert characters into a terminal on a 64-bit…
PriorityP351high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EXPLOIT
EPSS
3.70%
88.5th percentile
A vulnerability in the seccomp filters of Canonical snapd before version 2.37.4 allows a strict mode snap to insert characters into a terminal on a 64-bit host. The seccomp rules were generated to match 64-bit ioctl(2) commands on a 64-bit platform; however, the Linux kernel only uses the lower 32 bits to determine which ioctl(2) commands to run. This issue affects: Canonical snapd versions prior to 2.37.4.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | snapd | < 2.37.4 | 2.37.4 |
| canonical | snapd | >= unspecified < 2.37.4 | 2.37.4 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | snapd | < snapd 2.37.4-1 (bookworm) | snapd 2.37.4-1 (bookworm) |
| snapcraft | snapd | >= 0 < 2.37.4-1 | 2.37.4-1 |
| snapcraft | snapd | >= 0 < 2.37.4-1 | 2.37.4-1 |
| snapcraft | snapd | >= 0 < 2.37.4-1 | 2.37.4-1 |
| snapcraft | snapd | >= 0 < 2.37.4-1 | 2.37.4-1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv3.05.7MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
snapd vulnerability
vendor_ubuntu·2019-03-21
CVE-2019-7303 snapd vulnerability
Title: snapd vulnerability
Summary: An intended access restriction in snapd could be bypassed by strict mode
snaps on 64 bit architectures.
The snapd default seccomp filter for strict mode snaps blocks the use of
the ioctl() system call when used with TIOCSTI as the second argument to
the system call. Jann Horn discovered that this restriction could be
circumvented on 64 bit architectures. A malicious snap could exploit this
to bypass intended access restrictions to insert characters into the
terminal's input queue. On Ubuntu, snapd typically will have already
automatically refreshed itself to snapd 2.37.4 which is unaffected.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2019-7303: snapd - A vulnerability in the seccomp filters of Canonical snapd before version 2.37.4 ...
vendor_debian·2019·CVSS 7.5
CVE-2019-7303 [HIGH] CVE-2019-7303: snapd - A vulnerability in the seccomp filters of Canonical snapd before version 2.37.4 ...
A vulnerability in the seccomp filters of Canonical snapd before version 2.37.4 allows a strict mode snap to insert characters into a terminal on a 64-bit host. The seccomp rules were generated to match 64-bit ioctl(2) commands on a 64-bit platform; however, the Linux kernel only uses the lower 32 bits to determine which ioctl(2) commands to run. This issue affects: Canonical snapd versions prior to 2.37.4.
Scope: local
bookworm: resolved (fixed in 2.37.4-1)
bullseye: resolved (fixed in 2.37.4-1)
forky: resolved (fixed in 2.37.4-1)
sid: resolved (fixed in 2.37.4-1)
trixie: resolved (fixed in 2.37.4-1)
GHSA
GHSA-hhhq-qgvm-w5hp: A vulnerability in the seccomp filters of Canonical snapd before version 2
ghsa_unreviewed·2022-05-24
CVE-2019-7303 [HIGH] GHSA-hhhq-qgvm-w5hp: A vulnerability in the seccomp filters of Canonical snapd before version 2
A vulnerability in the seccomp filters of Canonical snapd before version 2.37.4 allows a strict mode snap to insert characters into a terminal on a 64-bit host. The seccomp rules were generated to match 64-bit ioctl(2) commands on a 64-bit platform; however, the Linux kernel only uses the lower 32 bits to determine which ioctl(2) commands to run. This issue affects: Canonical snapd versions prior to 2.37.4.
OSV
CVE-2019-7303: A vulnerability in the seccomp filters of Canonical snapd before version 2
osv·2019-04-23·CVSS 7.5
CVE-2019-7303 [HIGH] CVE-2019-7303: A vulnerability in the seccomp filters of Canonical snapd before version 2
A vulnerability in the seccomp filters of Canonical snapd before version 2.37.4 allows a strict mode snap to insert characters into a terminal on a 64-bit host. The seccomp rules were generated to match 64-bit ioctl(2) commands on a 64-bit platform; however, the Linux kernel only uses the lower 32 bits to determine which ioctl(2) commands to run. This issue affects: Canonical snapd versions prior to 2.37.4.
No detection rules found.
No writeups or analysis indexed.
2019-04-23
Published