CVE-2021-44730
published 2022-02-17CVE-2021-44730: snapd 2.54.2 did not properly validate the location of the snap-confine binary. A local attacker who can hardlink this binary to another location to cause…
PriorityP346high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.35%
27.3th percentile
snapd 2.54.2 did not properly validate the location of the snap-confine binary. A local attacker who can hardlink this binary to another location to cause snap-confine to execute other arbitrary binaries and hence gain privilege escalation. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | snapd | <= 2.54.2 | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical_ltd | snapd | unspecified – 2.54.2 | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | snapd | < snapd 2.54.3-1 (bookworm) | snapd 2.54.3-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| snapcraft | snapd | >= 0 < 2.49-1+deb11u1 | 2.49-1+deb11u1 |
| snapcraft | snapd | >= 0 < 2.54.3-1 | 2.54.3-1 |
| snapcraft | snapd | >= 0 < 2.54.3-1 | 2.54.3-1 |
| snapcraft | snapd | >= 0 < 2.54.3-1 | 2.54.3-1 |
| snapcraft | snapd | >= 0 < 2.54.3+18.04 | 2.54.3+18.04 |
| snapcraft | snapd | >= 0 < 2.54.3+18.04.2ubuntu0.2 | 2.54.3+18.04.2ubuntu0.2 |
| snapcraft | snapd | >= 0 < 2.54.3+20.04 | 2.54.3+20.04 |
| snapcraft | snapd | >= 0 < 2.54.3+20.04.1 | 2.54.3+20.04.1 |
| snapcraft | snapd | >= 0 < 2.54.3+20.04.1ubuntu0.2 | 2.54.3+20.04.1ubuntu0.2 |
| snapcraft | snapd | >= 0 < 2.54.3+14.04~esm1 | 2.54.3+14.04~esm1 |
| snapcraft | snapd | >= 0 < 2.54.3+14.04.0ubuntu0.1~esm3 | 2.54.3+14.04.0ubuntu0.1~esm3 |
| snapcraft | snapd | >= 0 < 2.54.3+16.04~esm2 | 2.54.3+16.04~esm2 |
| snapcraft | snapd | >= 0 < 2.54.3+16.04.0ubuntu0.1~esm4 | 2.54.3+16.04.0ubuntu0.1~esm4 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_debian7.8HIGH
vendor_ubuntu3.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
snapd regression
osv·2022-02-24·CVSS 5.5
CVE-2021-3155 [MEDIUM] snapd regression
snapd regression
USN-5292-1 fixed a vulnerability in snapd. Unfortunately that update introduced
a regression that could break the fish shell. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
James Troup discovered that snap did not properly manage the permissions for
the snap directories. A local attacker could possibly use this issue to expose
sensitive information. (CVE-2021-3155)
Ian Johnson discovered that snapd did not properly validate content interfaces
and layout paths. A local attacker could possibly use this issue to inject
arbitrary AppArmor policy rules, resulting in a bypass of intended access
restrictions. (CVE-2021-4120)
The Qualys Research Team discovered that snapd did not properly validate the
location of the snap-confin
GHSA
GHSA-f6xc-44hh-rf46: snapd 2
ghsa_unreviewed·2022-02-19
CVE-2021-44730 [HIGH] CWE-59 GHSA-f6xc-44hh-rf46: snapd 2
snapd 2.54.2 did not properly validate the location of the snap-confine binary. A local attacker who can hardlink this binary to another location to cause snap-confine to execute other arbitrary binaries and hence gain privilege escalation. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1
OSV
snapd vulnerabilities
osv·2022-02-18·CVSS 5.5
CVE-2021-3155 [MEDIUM] snapd vulnerabilities
snapd vulnerabilities
USN-5292-1 fixed vulnerabilities in snapd. This update provides the
corresponding update for the riscv64 architecture.
Original advisory details:
James Troup discovered that snap did not properly manage the permissions for
the snap directories. A local attacker could possibly use this issue to expose
sensitive information. (CVE-2021-3155)
Ian Johnson discovered that snapd did not properly validate content interfaces
and layout paths. A local attacker could possibly use this issue to inject
arbitrary AppArmor policy rules, resulting in a bypass of intended access
restrictions. (CVE-2021-4120)
The Qualys Research Team discovered that snapd did not properly validate the
location of the snap-confine binary. A local attacker could possibly use this
issue to execute ot
OSV
snapd vulnerabilities
osv·2022-02-18·CVSS 5.5
CVE-2021-3155 [MEDIUM] snapd vulnerabilities
snapd vulnerabilities
USN-5292-1 fixed several vulnerabilities in snapd. This update provides the
corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
James Troup discovered that snap did not properly manage the permissions for
the snap directories. A local attacker could possibly use this issue to expose
sensitive information. (CVE-2021-3155)
Ian Johnson discovered that snapd did not properly validate content interfaces
and layout paths. A local attacker could possibly use this issue to inject
arbitrary AppArmor policy rules, resulting in a bypass of intended access
restrictions. (CVE-2021-4120)
The Qualys Research Team discovered that snapd did not properly validate the
location of the snap-confine binary. A local attacker could possibly use thi
OSV
CVE-2021-44730: snapd 2
osv·2022-02-17·CVSS 8.8
CVE-2021-44730 [HIGH] CVE-2021-44730: snapd 2
snapd 2.54.2 did not properly validate the location of the snap-confine binary. A local attacker who can hardlink this binary to another location to cause snap-confine to execute other arbitrary binaries and hence gain privilege escalation. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1
OSV
snapd vulnerabilities
osv·2022-02-17·CVSS 5.5
CVE-2021-3155 [MEDIUM] snapd vulnerabilities
snapd vulnerabilities
James Troup discovered that snap did not properly manage the permissions for
the snap directories. A local attacker could possibly use this issue to expose
sensitive information. (CVE-2021-3155)
Ian Johnson discovered that snapd did not properly validate content interfaces
and layout paths. A local attacker could possibly use this issue to inject
arbitrary AppArmor policy rules, resulting in a bypass of intended access
restrictions. (CVE-2021-4120)
The Qualys Research Team discovered that snapd did not properly validate the
location of the snap-confine binary. A local attacker could possibly use this
issue to execute other arbitrary binaries and escalate privileges.
(CVE-2021-44730)
The Qualys Research Team discovered that a race condition existed in the snapd
sna
Ubuntu
snapd regression
vendor_ubuntu·2022-02-24·CVSS 3.8
CVE-2021-3155 [LOW] snapd regression
Title: snapd regression
Summary: USN-5292-1 introduced a regression in snapd.
USN-5292-1 fixed a vulnerability in snapd. Unfortunately that update introduced
a regression that could break the fish shell. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
James Troup discovered that snap did not properly manage the permissions for
the snap directories. A local attacker could possibly use this issue to expose
sensitive information. (CVE-2021-3155)
Ian Johnson discovered that snapd did not properly validate content interfaces
and layout paths. A local attacker could possibly use this issue to inject
arbitrary AppArmor policy rules, resulting in a bypass of intended access
restrictions. (CVE-2021-4120)
The Qualys Research Team discovered that s
Ubuntu
snapd vulnerabilities
vendor_ubuntu·2022-02-18·CVSS 3.8
CVE-2021-3155 [LOW] snapd vulnerabilities
Title: snapd vulnerabilities
Summary: Several security issues were fixed in snapd.
USN-5292-1 fixed vulnerabilities in snapd. This update provides the
corresponding update for the riscv64 architecture.
Original advisory details:
James Troup discovered that snap did not properly manage the permissions for
the snap directories. A local attacker could possibly use this issue to expose
sensitive information. (CVE-2021-3155)
Ian Johnson discovered that snapd did not properly validate content interfaces
and layout paths. A local attacker could possibly use this issue to inject
arbitrary AppArmor policy rules, resulting in a bypass of intended access
restrictions. (CVE-2021-4120)
The Qualys Research Team discovered that snapd did not properly validate the
location of the snap-confine binary
Ubuntu
snapd vulnerabilities
vendor_ubuntu·2022-02-18·CVSS 3.8
CVE-2021-3155 [LOW] snapd vulnerabilities
Title: snapd vulnerabilities
Summary: Several security issues were fixed in snapd.
USN-5292-1 fixed several vulnerabilities in snapd. This update provides the
corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
James Troup discovered that snap did not properly manage the permissions for
the snap directories. A local attacker could possibly use this issue to expose
sensitive information. (CVE-2021-3155)
Ian Johnson discovered that snapd did not properly validate content interfaces
and layout paths. A local attacker could possibly use this issue to inject
arbitrary AppArmor policy rules, resulting in a bypass of intended access
restrictions. (CVE-2021-4120)
The Qualys Research Team discovered that snapd did not properly validate the
location of th
Ubuntu
snapd vulnerabilities
vendor_ubuntu·2022-02-17·CVSS 3.8
CVE-2021-44730 [LOW] snapd vulnerabilities
Title: snapd vulnerabilities
Summary: Several security issues were fixed in snapd.
James Troup discovered that snap did not properly manage the permissions for
the snap directories. A local attacker could possibly use this issue to expose
sensitive information. (CVE-2021-3155)
Ian Johnson discovered that snapd did not properly validate content interfaces
and layout paths. A local attacker could possibly use this issue to inject
arbitrary AppArmor policy rules, resulting in a bypass of intended access
restrictions. (CVE-2021-4120)
The Qualys Research Team discovered that snapd did not properly validate the
location of the snap-confine binary. A local attacker could possibly use this
issue to execute other arbitrary binaries and escalate privileges.
(CVE-2021-44730)
The Qualys Research
Debian
CVE-2021-44730: snapd - snapd 2.54.2 did not properly validate the location of the snap-confine binary. ...
vendor_debian·2021·CVSS 7.8
CVE-2021-44730 [HIGH] CVE-2021-44730: snapd - snapd 2.54.2 did not properly validate the location of the snap-confine binary. ...
snapd 2.54.2 did not properly validate the location of the snap-confine binary. A local attacker who can hardlink this binary to another location to cause snap-confine to execute other arbitrary binaries and hence gain privilege escalation. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1
Scope: local
bookworm: resolved (fixed in 2.54.3-1)
bullseye: resolved (fixed in 2.49-1+deb11u1)
forky: resolved (fixed in 2.54.3-1)
sid: resolved (fixed in 2.54.3-1)
trixie: resolved (fixed in 2.54.3-1)
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2022/02/18/2http://www.openwall.com/lists/oss-security/2022/02/23/1https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3QTBN7LLZISXIA4KU4UKDR27Q5PXDS2U/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XCGHG6LJAVJJ72TMART6A7N4Z6MSTGI7/https://ubuntu.com/security/notices/USN-5292-1https://www.debian.org/security/2022/dsa-5080http://www.openwall.com/lists/oss-security/2022/02/18/2http://www.openwall.com/lists/oss-security/2022/02/23/1https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3QTBN7LLZISXIA4KU4UKDR27Q5PXDS2U/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XCGHG6LJAVJJ72TMART6A7N4Z6MSTGI7/https://ubuntu.com/security/notices/USN-5292-1https://www.debian.org/security/2022/dsa-5080
2022-02-17
Published