cbcvebase.
CVE-2021-4120
published 2022-02-17

CVE-2021-4120: snapd 2.54.2 fails to perform sufficient validation of snap content interface and layout paths, resulting in the ability for snaps to inject arbitrary AppArmor…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.44%
35.2th percentile
snapd 2.54.2 fails to perform sufficient validation of snap content interface and layout paths, resulting in the ability for snaps to inject arbitrary AppArmor policy rules via malformed content interface and layout declarations and hence escape strict snap confinement. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1

Affected

21 ranges
VendorProductVersion rangeFixed in
canonicalsnapd<= 2.54.2
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonical_ltdsnapdunspecified – 2.54.2
debiansnapd< snapd 2.54.3-1 (bookworm)snapd 2.54.3-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
snapcraftsnapd>= 0 < 2.49-1+deb11u12.49-1+deb11u1
snapcraftsnapd>= 0 < 2.54.3-12.54.3-1
snapcraftsnapd>= 0 < 2.54.3-12.54.3-1
snapcraftsnapd>= 0 < 2.54.3-12.54.3-1
snapcraftsnapd>= 0 < 2.54.3+18.042.54.3+18.04
snapcraftsnapd>= 0 < 2.54.3+18.04.2ubuntu0.22.54.3+18.04.2ubuntu0.2
snapcraftsnapd>= 0 < 2.54.3+20.042.54.3+20.04
snapcraftsnapd>= 0 < 2.54.3+20.04.12.54.3+20.04.1
snapcraftsnapd>= 0 < 2.54.3+20.04.1ubuntu0.22.54.3+20.04.1ubuntu0.2
snapcraftsnapd>= 0 < 2.54.3+14.04~esm12.54.3+14.04~esm1
snapcraftsnapd>= 0 < 2.54.3+14.04.0ubuntu0.1~esm32.54.3+14.04.0ubuntu0.1~esm3
snapcraftsnapd>= 0 < 2.54.3+16.04~esm22.54.3+16.04~esm2
snapcraftsnapd>= 0 < 2.54.3+16.04.0ubuntu0.1~esm42.54.3+16.04.0ubuntu0.1~esm4

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian8.2HIGH
vendor_ubuntu3.8LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.