CVE-2021-3155
published 2022-02-17CVE-2021-3155: snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local attacker to…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.26%
17.5th percentile
snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local attacker to read information that should have been private. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | snapd | < 2.54.3 | 2.54.3 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical_ltd | snapd | unspecified – 2.54.2 | — |
| debian | snapd | < snapd 2.54-1 (bookworm) | snapd 2.54-1 (bookworm) |
| snapcraft | snapd | >= 0 < 2.54-1 | 2.54-1 |
| snapcraft | snapd | >= 0 < 2.54-1 | 2.54-1 |
| snapcraft | snapd | >= 0 < 2.54-1 | 2.54-1 |
| snapcraft | snapd | >= 0 < 2.54.3+18.04 | 2.54.3+18.04 |
| snapcraft | snapd | >= 0 < 2.54.3+18.04.2ubuntu0.2 | 2.54.3+18.04.2ubuntu0.2 |
| snapcraft | snapd | >= 0 < 2.54.3+20.04 | 2.54.3+20.04 |
| snapcraft | snapd | >= 0 < 2.54.3+20.04.1 | 2.54.3+20.04.1 |
| snapcraft | snapd | >= 0 < 2.54.3+20.04.1ubuntu0.2 | 2.54.3+20.04.1ubuntu0.2 |
| snapcraft | snapd | >= 0 < 2.54.3+14.04~esm1 | 2.54.3+14.04~esm1 |
| snapcraft | snapd | >= 0 < 2.54.3+14.04.0ubuntu0.1~esm3 | 2.54.3+14.04.0ubuntu0.1~esm3 |
| snapcraft | snapd | >= 0 < 2.54.3+16.04~esm2 | 2.54.3+16.04~esm2 |
| snapcraft | snapd | >= 0 < 2.54.3+16.04.0ubuntu0.1~esm4 | 2.54.3+16.04.0ubuntu0.1~esm4 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian3.8LOW
vendor_ubuntu3.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
snapd regression
osv·2022-02-24·CVSS 5.5
CVE-2021-3155 [MEDIUM] snapd regression
snapd regression
USN-5292-1 fixed a vulnerability in snapd. Unfortunately that update introduced
a regression that could break the fish shell. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
James Troup discovered that snap did not properly manage the permissions for
the snap directories. A local attacker could possibly use this issue to expose
sensitive information. (CVE-2021-3155)
Ian Johnson discovered that snapd did not properly validate content interfaces
and layout paths. A local attacker could possibly use this issue to inject
arbitrary AppArmor policy rules, resulting in a bypass of intended access
restrictions. (CVE-2021-4120)
The Qualys Research Team discovered that snapd did not properly validate the
location of the snap-confin
GHSA
GHSA-7x7f-q6wr-wc4w: snapd 2
ghsa_unreviewed·2022-02-19
CVE-2021-3155 [MEDIUM] CWE-276 GHSA-7x7f-q6wr-wc4w: snapd 2
snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local attacker to read information that should have been private. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1
OSV
snapd vulnerabilities
osv·2022-02-18·CVSS 5.5
CVE-2021-3155 [MEDIUM] snapd vulnerabilities
snapd vulnerabilities
USN-5292-1 fixed vulnerabilities in snapd. This update provides the
corresponding update for the riscv64 architecture.
Original advisory details:
James Troup discovered that snap did not properly manage the permissions for
the snap directories. A local attacker could possibly use this issue to expose
sensitive information. (CVE-2021-3155)
Ian Johnson discovered that snapd did not properly validate content interfaces
and layout paths. A local attacker could possibly use this issue to inject
arbitrary AppArmor policy rules, resulting in a bypass of intended access
restrictions. (CVE-2021-4120)
The Qualys Research Team discovered that snapd did not properly validate the
location of the snap-confine binary. A local attacker could possibly use this
issue to execute ot
OSV
snapd vulnerabilities
osv·2022-02-18·CVSS 5.5
CVE-2021-3155 [MEDIUM] snapd vulnerabilities
snapd vulnerabilities
USN-5292-1 fixed several vulnerabilities in snapd. This update provides the
corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
James Troup discovered that snap did not properly manage the permissions for
the snap directories. A local attacker could possibly use this issue to expose
sensitive information. (CVE-2021-3155)
Ian Johnson discovered that snapd did not properly validate content interfaces
and layout paths. A local attacker could possibly use this issue to inject
arbitrary AppArmor policy rules, resulting in a bypass of intended access
restrictions. (CVE-2021-4120)
The Qualys Research Team discovered that snapd did not properly validate the
location of the snap-confine binary. A local attacker could possibly use thi
OSV
snapd vulnerabilities
osv·2022-02-17·CVSS 5.5
CVE-2021-3155 [MEDIUM] snapd vulnerabilities
snapd vulnerabilities
James Troup discovered that snap did not properly manage the permissions for
the snap directories. A local attacker could possibly use this issue to expose
sensitive information. (CVE-2021-3155)
Ian Johnson discovered that snapd did not properly validate content interfaces
and layout paths. A local attacker could possibly use this issue to inject
arbitrary AppArmor policy rules, resulting in a bypass of intended access
restrictions. (CVE-2021-4120)
The Qualys Research Team discovered that snapd did not properly validate the
location of the snap-confine binary. A local attacker could possibly use this
issue to execute other arbitrary binaries and escalate privileges.
(CVE-2021-44730)
The Qualys Research Team discovered that a race condition existed in the snapd
sna
OSV
CVE-2021-3155: snapd 2
osv·2022-02-17·CVSS 5.5
CVE-2021-3155 [MEDIUM] CVE-2021-3155: snapd 2
snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local attacker to read information that should have been private. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1
Ubuntu
snapd regression
vendor_ubuntu·2022-02-24·CVSS 3.8
CVE-2021-3155 [LOW] snapd regression
Title: snapd regression
Summary: USN-5292-1 introduced a regression in snapd.
USN-5292-1 fixed a vulnerability in snapd. Unfortunately that update introduced
a regression that could break the fish shell. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
James Troup discovered that snap did not properly manage the permissions for
the snap directories. A local attacker could possibly use this issue to expose
sensitive information. (CVE-2021-3155)
Ian Johnson discovered that snapd did not properly validate content interfaces
and layout paths. A local attacker could possibly use this issue to inject
arbitrary AppArmor policy rules, resulting in a bypass of intended access
restrictions. (CVE-2021-4120)
The Qualys Research Team discovered that s
Ubuntu
snapd vulnerabilities
vendor_ubuntu·2022-02-18·CVSS 3.8
CVE-2021-3155 [LOW] snapd vulnerabilities
Title: snapd vulnerabilities
Summary: Several security issues were fixed in snapd.
USN-5292-1 fixed vulnerabilities in snapd. This update provides the
corresponding update for the riscv64 architecture.
Original advisory details:
James Troup discovered that snap did not properly manage the permissions for
the snap directories. A local attacker could possibly use this issue to expose
sensitive information. (CVE-2021-3155)
Ian Johnson discovered that snapd did not properly validate content interfaces
and layout paths. A local attacker could possibly use this issue to inject
arbitrary AppArmor policy rules, resulting in a bypass of intended access
restrictions. (CVE-2021-4120)
The Qualys Research Team discovered that snapd did not properly validate the
location of the snap-confine binary
Ubuntu
snapd vulnerabilities
vendor_ubuntu·2022-02-18·CVSS 3.8
CVE-2021-3155 [LOW] snapd vulnerabilities
Title: snapd vulnerabilities
Summary: Several security issues were fixed in snapd.
USN-5292-1 fixed several vulnerabilities in snapd. This update provides the
corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
James Troup discovered that snap did not properly manage the permissions for
the snap directories. A local attacker could possibly use this issue to expose
sensitive information. (CVE-2021-3155)
Ian Johnson discovered that snapd did not properly validate content interfaces
and layout paths. A local attacker could possibly use this issue to inject
arbitrary AppArmor policy rules, resulting in a bypass of intended access
restrictions. (CVE-2021-4120)
The Qualys Research Team discovered that snapd did not properly validate the
location of th
Ubuntu
snapd vulnerabilities
vendor_ubuntu·2022-02-17·CVSS 3.8
CVE-2021-44730 [LOW] snapd vulnerabilities
Title: snapd vulnerabilities
Summary: Several security issues were fixed in snapd.
James Troup discovered that snap did not properly manage the permissions for
the snap directories. A local attacker could possibly use this issue to expose
sensitive information. (CVE-2021-3155)
Ian Johnson discovered that snapd did not properly validate content interfaces
and layout paths. A local attacker could possibly use this issue to inject
arbitrary AppArmor policy rules, resulting in a bypass of intended access
restrictions. (CVE-2021-4120)
The Qualys Research Team discovered that snapd did not properly validate the
location of the snap-confine binary. A local attacker could possibly use this
issue to execute other arbitrary binaries and escalate privileges.
(CVE-2021-44730)
The Qualys Research
Debian
CVE-2021-3155: snapd - snapd 2.54.2 and earlier created ~/snap directories in user home directories wit...
vendor_debian·2021·CVSS 3.8
CVE-2021-3155 [LOW] CVE-2021-3155: snapd - snapd 2.54.2 and earlier created ~/snap directories in user home directories wit...
snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local attacker to read information that should have been private. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1
Scope: local
bookworm: resolved (fixed in 2.54-1)
bullseye: open
forky: resolved (fixed in 2.54-1)
sid: resolved (fixed in 2.54-1)
trixie: resolved (fixed in 2.54-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/snapcore/snapd/commit/6bcaeeccd16ed8298a301dd92f6907f88c24cc85https://github.com/snapcore/snapd/commit/7d2a966620002149891446a53cf114804808dccahttps://ubuntu.com/security/notices/USN-5292-1https://github.com/snapcore/snapd/commit/6bcaeeccd16ed8298a301dd92f6907f88c24cc85https://github.com/snapcore/snapd/commit/7d2a966620002149891446a53cf114804808dccahttps://ubuntu.com/security/notices/USN-5292-1
2022-02-17
Published