CVE-2021-44731
published 2022-02-17CVE-2021-44731: A race condition existed in the snapd 2.54.2 snap-confine binary when preparing a private mount namespace for a snap. This could allow a local attacker to gain…
PriorityP345high7.8CVSS 3.1
AVLACHPRLUINSCCHIHAH
EPSS
0.95%
57.2th percentile
A race condition existed in the snapd 2.54.2 snap-confine binary when preparing a private mount namespace for a snap. This could allow a local attacker to gain root privileges by bind-mounting their own contents inside the snap's private mount namespace and causing snap-confine to execute arbitrary code and hence gain privilege escalation. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | snapd | <= 2.54.2 | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical_ltd | snapd | unspecified – 2.54.2 | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | snapd | < snapd 2.54.3-1 (bookworm) | snapd 2.54.3-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| snapcraft | snapd | >= 0 < 2.49-1+deb11u1 | 2.49-1+deb11u1 |
| snapcraft | snapd | >= 0 < 2.54.3-1 | 2.54.3-1 |
| snapcraft | snapd | >= 0 < 2.54.3-1 | 2.54.3-1 |
| snapcraft | snapd | >= 0 < 2.54.3-1 | 2.54.3-1 |
| snapcraft | snapd | >= 0 < 2.54.3+18.04 | 2.54.3+18.04 |
| snapcraft | snapd | >= 0 < 2.54.3+18.04.2ubuntu0.2 | 2.54.3+18.04.2ubuntu0.2 |
| snapcraft | snapd | >= 0 < 2.54.3+20.04 | 2.54.3+20.04 |
| snapcraft | snapd | >= 0 < 2.54.3+20.04.1 | 2.54.3+20.04.1 |
| snapcraft | snapd | >= 0 < 2.54.3+20.04.1ubuntu0.2 | 2.54.3+20.04.1ubuntu0.2 |
| snapcraft | snapd | >= 0 < 2.54.3+14.04~esm1 | 2.54.3+14.04~esm1 |
| snapcraft | snapd | >= 0 < 2.54.3+14.04.0ubuntu0.1~esm3 | 2.54.3+14.04.0ubuntu0.1~esm3 |
| snapcraft | snapd | >= 0 < 2.54.3+16.04~esm2 | 2.54.3+16.04~esm2 |
| snapcraft | snapd | >= 0 < 2.54.3+16.04.0ubuntu0.1~esm4 | 2.54.3+16.04.0ubuntu0.1~esm4 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_ubuntu3.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
snapd regression
vendor_ubuntu·2022-02-24·CVSS 3.8
CVE-2021-3155 [LOW] snapd regression
Title: snapd regression
Summary: USN-5292-1 introduced a regression in snapd.
USN-5292-1 fixed a vulnerability in snapd. Unfortunately that update introduced
a regression that could break the fish shell. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
James Troup discovered that snap did not properly manage the permissions for
the snap directories. A local attacker could possibly use this issue to expose
sensitive information. (CVE-2021-3155)
Ian Johnson discovered that snapd did not properly validate content interfaces
and layout paths. A local attacker could possibly use this issue to inject
arbitrary AppArmor policy rules, resulting in a bypass of intended access
restrictions. (CVE-2021-4120)
The Qualys Research Team discovered that s
Ubuntu
snapd vulnerabilities
vendor_ubuntu·2022-02-18·CVSS 3.8
CVE-2021-3155 [LOW] snapd vulnerabilities
Title: snapd vulnerabilities
Summary: Several security issues were fixed in snapd.
USN-5292-1 fixed vulnerabilities in snapd. This update provides the
corresponding update for the riscv64 architecture.
Original advisory details:
James Troup discovered that snap did not properly manage the permissions for
the snap directories. A local attacker could possibly use this issue to expose
sensitive information. (CVE-2021-3155)
Ian Johnson discovered that snapd did not properly validate content interfaces
and layout paths. A local attacker could possibly use this issue to inject
arbitrary AppArmor policy rules, resulting in a bypass of intended access
restrictions. (CVE-2021-4120)
The Qualys Research Team discovered that snapd did not properly validate the
location of the snap-confine binary
Ubuntu
snapd vulnerabilities
vendor_ubuntu·2022-02-18·CVSS 3.8
CVE-2021-3155 [LOW] snapd vulnerabilities
Title: snapd vulnerabilities
Summary: Several security issues were fixed in snapd.
USN-5292-1 fixed several vulnerabilities in snapd. This update provides the
corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
James Troup discovered that snap did not properly manage the permissions for
the snap directories. A local attacker could possibly use this issue to expose
sensitive information. (CVE-2021-3155)
Ian Johnson discovered that snapd did not properly validate content interfaces
and layout paths. A local attacker could possibly use this issue to inject
arbitrary AppArmor policy rules, resulting in a bypass of intended access
restrictions. (CVE-2021-4120)
The Qualys Research Team discovered that snapd did not properly validate the
location of th
Ubuntu
snapd vulnerabilities
vendor_ubuntu·2022-02-17·CVSS 3.8
CVE-2021-44730 [LOW] snapd vulnerabilities
Title: snapd vulnerabilities
Summary: Several security issues were fixed in snapd.
James Troup discovered that snap did not properly manage the permissions for
the snap directories. A local attacker could possibly use this issue to expose
sensitive information. (CVE-2021-3155)
Ian Johnson discovered that snapd did not properly validate content interfaces
and layout paths. A local attacker could possibly use this issue to inject
arbitrary AppArmor policy rules, resulting in a bypass of intended access
restrictions. (CVE-2021-4120)
The Qualys Research Team discovered that snapd did not properly validate the
location of the snap-confine binary. A local attacker could possibly use this
issue to execute other arbitrary binaries and escalate privileges.
(CVE-2021-44730)
The Qualys Research
Debian
CVE-2021-44731: snapd - A race condition existed in the snapd 2.54.2 snap-confine binary when preparing ...
vendor_debian·2021·CVSS 7.8
CVE-2021-44731 [HIGH] CVE-2021-44731: snapd - A race condition existed in the snapd 2.54.2 snap-confine binary when preparing ...
A race condition existed in the snapd 2.54.2 snap-confine binary when preparing a private mount namespace for a snap. This could allow a local attacker to gain root privileges by bind-mounting their own contents inside the snap's private mount namespace and causing snap-confine to execute arbitrary code and hence gain privilege escalation. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1
Scope: local
bookworm: resolved (fixed in 2.54.3-1)
bullseye: resolved (fixed in 2.49-1+deb11u1)
forky: resolved (fixed in 2.54.3-1)
sid: resolved (fixed in 2.54.3-1)
trixie: resolved (fixed in 2.54.3-1)
OSV
snapd regression
osv·2022-02-24·CVSS 5.5
CVE-2021-3155 [MEDIUM] snapd regression
snapd regression
USN-5292-1 fixed a vulnerability in snapd. Unfortunately that update introduced
a regression that could break the fish shell. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
James Troup discovered that snap did not properly manage the permissions for
the snap directories. A local attacker could possibly use this issue to expose
sensitive information. (CVE-2021-3155)
Ian Johnson discovered that snapd did not properly validate content interfaces
and layout paths. A local attacker could possibly use this issue to inject
arbitrary AppArmor policy rules, resulting in a bypass of intended access
restrictions. (CVE-2021-4120)
The Qualys Research Team discovered that snapd did not properly validate the
location of the snap-confin
GHSA
GHSA-m3j9-xfh2-hrgc: A race condition existed in the snapd 2
ghsa_unreviewed·2022-02-19
CVE-2021-44731 [HIGH] CWE-362 GHSA-m3j9-xfh2-hrgc: A race condition existed in the snapd 2
A race condition existed in the snapd 2.54.2 snap-confine binary when preparing a private mount namespace for a snap. This could allow a local attacker to gain root privileges by bind-mounting their own contents inside the snap's private mount namespace and causing snap-confine to execute arbitrary code and hence gain privilege escalation. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1
OSV
snapd vulnerabilities
osv·2022-02-18·CVSS 5.5
CVE-2021-3155 [MEDIUM] snapd vulnerabilities
snapd vulnerabilities
USN-5292-1 fixed vulnerabilities in snapd. This update provides the
corresponding update for the riscv64 architecture.
Original advisory details:
James Troup discovered that snap did not properly manage the permissions for
the snap directories. A local attacker could possibly use this issue to expose
sensitive information. (CVE-2021-3155)
Ian Johnson discovered that snapd did not properly validate content interfaces
and layout paths. A local attacker could possibly use this issue to inject
arbitrary AppArmor policy rules, resulting in a bypass of intended access
restrictions. (CVE-2021-4120)
The Qualys Research Team discovered that snapd did not properly validate the
location of the snap-confine binary. A local attacker could possibly use this
issue to execute ot
OSV
snapd vulnerabilities
osv·2022-02-18·CVSS 5.5
CVE-2021-3155 [MEDIUM] snapd vulnerabilities
snapd vulnerabilities
USN-5292-1 fixed several vulnerabilities in snapd. This update provides the
corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
James Troup discovered that snap did not properly manage the permissions for
the snap directories. A local attacker could possibly use this issue to expose
sensitive information. (CVE-2021-3155)
Ian Johnson discovered that snapd did not properly validate content interfaces
and layout paths. A local attacker could possibly use this issue to inject
arbitrary AppArmor policy rules, resulting in a bypass of intended access
restrictions. (CVE-2021-4120)
The Qualys Research Team discovered that snapd did not properly validate the
location of the snap-confine binary. A local attacker could possibly use thi
OSV
snapd vulnerabilities
osv·2022-02-17·CVSS 5.5
CVE-2021-3155 [MEDIUM] snapd vulnerabilities
snapd vulnerabilities
James Troup discovered that snap did not properly manage the permissions for
the snap directories. A local attacker could possibly use this issue to expose
sensitive information. (CVE-2021-3155)
Ian Johnson discovered that snapd did not properly validate content interfaces
and layout paths. A local attacker could possibly use this issue to inject
arbitrary AppArmor policy rules, resulting in a bypass of intended access
restrictions. (CVE-2021-4120)
The Qualys Research Team discovered that snapd did not properly validate the
location of the snap-confine binary. A local attacker could possibly use this
issue to execute other arbitrary binaries and escalate privileges.
(CVE-2021-44730)
The Qualys Research Team discovered that a race condition existed in the snapd
sna
OSV
CVE-2021-44731: A race condition existed in the snapd 2
osv·2022-02-17·CVSS 7.8
CVE-2021-44731 [HIGH] CVE-2021-44731: A race condition existed in the snapd 2
A race condition existed in the snapd 2.54.2 snap-confine binary when preparing a private mount namespace for a snap. This could allow a local attacker to gain root privileges by bind-mounting their own contents inside the snap's private mount namespace and causing snap-confine to execute arbitrary code and hence gain privilege escalation. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1
No detection rules found.
No public exploits indexed.
Qualys
Snapd Race Condition Vulnerability in snap-confine’s must_mkdir_and_open_with_perms() (CVE-2022-3328) | Qualys
blogs_qualys·2022-11-30·CVSS 7.8
CVE-2022-3328 [HIGH] Snapd Race Condition Vulnerability in snap-confine’s must_mkdir_and_open_with_perms() (CVE-2022-3328) | Qualys
#### Table of Contents
- What is snap-confine?
- Potential Impact
- The technical details of snap-confine vulnerability can be found at:
- Disclosure Timeline
- Qualys QID Coverage
- Discover Vulnerable Linux Servers Using Qualys Cloud Platform
- Vendor References
- Frequently Asked Questions (FAQs)
The Qualys Threat Research Unit (TRU) has discovered a new vulnerability in snap-confine function on Linux operating systems, a SUID-root program installed by default on Ubuntu. Qualys recommends that security teams apply the patch for this vulnerability as soon as possible.
In February 2022, Qualys Threat Research Unit (TRU) published CVE-2021-44731 in our “Lemmings” advisory. The vulnerability (CVE-2022-3328) was introduced in February 2022 by the patch for CVE-2021-44731)
The Qualys Thre
Qualys
Snapd Race Condition Vulnerability in snap-confine’s must_mkdir_and_open_with_perms() (CVE-2022-3328)
blogs_qualys·2022-11-30·CVSS 7.8
[HIGH] Snapd Race Condition Vulnerability in snap-confine’s must_mkdir_and_open_with_perms() (CVE-2022-3328)
## Table of Contents
What is snap-confine?
Potential Impact
The technical details of snap-confine vulnerability can be found at:
Disclosure Timeline
Qualys QID Coverage
Discover Vulnerable Linux Servers Using Qualys Cloud Platform
Vendor References
Frequently Asked Questions (FAQs)
The Qualys Threat Research Unit (TRU) has discovered a new vulnerability in snap-confine function on Linux operating systems, a SUID-root program installed by default on Ubuntu. Qualys recommends that security teams apply the patch for this vulnerability as soon as possible.
In February 2022, Qualys Threat Research Unit (TRU) published CVE-2021-44731 in our “Lemmings” advisory. The vulnerability (CVE-2022-3328) was introduced in February 2022 by the patch for CVE-2021-44731)
The Qualys Threat Research
Qualys
Oh Snap! More Lemmings: Local Privilege Escalation Vulnerability Discovered in snap-confine (CVE-2021-44731)
blogs_qualys·2022-02-17·CVSS 7.8
[HIGH] Oh Snap! More Lemmings: Local Privilege Escalation Vulnerability Discovered in snap-confine (CVE-2021-44731)
## Table of Contents
About snap-confine
Potential Impact of Oh Snap! More Lemmings Vulnerability
Vulnerability Disclosure Timeline
Proof of Concept Video of Oh Snap! More Lemmings Exploit
Vulnerability Summary
Technical Details of Oh Snap! More Lemmings Vulnerability
Solution: How to Patch the Oh Snap! More Lemmings Vulnerability
Discover Vulnerable Linux Servers Using Qualys VMDR
Detect Impacted Assets with Threat Protection
Track Vulnerability with VMDR Dashboard
Vendor References
Frequently Asked Questions (FAQs)
The Qualys Research Team has discovered multiple vulnerabilities in the snap-confine function on Linux operating systems, the most important of which can be exploited to escalate privilege to gain root privileges. Qualys recommends security teams apply patches for
Qualys
Oh Snap! More Lemmings: Local Privilege Escalation Vulnerability Discovered in snap-confine (CVE-2021-44731) | Qualys
blogs_qualys·2022-02-17·CVSS 7.8
CVE-2021-44731 [HIGH] Oh Snap! More Lemmings: Local Privilege Escalation Vulnerability Discovered in snap-confine (CVE-2021-44731) | Qualys
#### Table of Contents
- About snap-confine
- Potential Impact of Oh Snap! More Lemmings Vulnerability
- Vulnerability Disclosure Timeline
- Proof of Concept Video of Oh Snap! More Lemmings Exploit
- Vulnerability Summary
- Technical Details of Oh Snap! More Lemmings Vulnerability
- Solution: How to Patch the Oh Snap! More Lemmings Vulnerability
- Discover Vulnerable Linux Servers Using Qualys VMDR
- Detect Impacted Assets with Threat Protection
- Track Vulnerability with VMDR Dashboard
- Vendor References
- Frequently Asked Questions (FAQs)
The Qualys Research Team has discovered multiple vulnerabilities in the snap-confine function on Linux operating systems, the most important of which can be exploited to escalate privilege to gain root privileges. Qualys recommends security teams app
http://packetstormsecurity.com/files/170176/snap-confine-must_mkdir_and_open_with_perms-Race-Condition.htmlhttp://seclists.org/fulldisclosure/2022/Dec/4http://www.openwall.com/lists/oss-security/2022/02/18/2http://www.openwall.com/lists/oss-security/2022/02/23/1http://www.openwall.com/lists/oss-security/2022/02/23/2http://www.openwall.com/lists/oss-security/2022/11/30/2https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3QTBN7LLZISXIA4KU4UKDR27Q5PXDS2U/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XCGHG6LJAVJJ72TMART6A7N4Z6MSTGI7/https://ubuntu.com/security/notices/USN-5292-1https://www.debian.org/security/2022/dsa-5080http://packetstormsecurity.com/files/170176/snap-confine-must_mkdir_and_open_with_perms-Race-Condition.htmlhttp://seclists.org/fulldisclosure/2022/Dec/4http://www.openwall.com/lists/oss-security/2022/02/18/2http://www.openwall.com/lists/oss-security/2022/02/23/1http://www.openwall.com/lists/oss-security/2022/02/23/2http://www.openwall.com/lists/oss-security/2022/11/30/2https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3QTBN7LLZISXIA4KU4UKDR27Q5PXDS2U/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XCGHG6LJAVJJ72TMART6A7N4Z6MSTGI7/https://ubuntu.com/security/notices/USN-5292-1https://www.debian.org/security/2022/dsa-5080
2022-02-17
Published