cbcvebase.
CVE-2023-1523
published 2023-09-01

CVE-2023-1523: Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause arbitrary…

PriorityP262critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
1.45%
70.4th percentile
Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause arbitrary commands to be executed outside of the snap sandbox after the snap exits. Graphical terminal emulators like xterm, gnome-terminal and others are not affected - this can only be exploited when snaps are run on a virtual console.

Affected

11 ranges
VendorProductVersion rangeFixed in
canonicalsnapd< 2.59.52.59.5
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiansnapd< snapd 2.59.5-1 (forky)snapd 2.59.5-1 (forky)
github.comapptainer_apptainer>= 1.2.0 < 1.2.11.2.1
snapcraftsnapd>= 0 < 2.59.5-12.59.5-1
snapcraftsnapd>= 0 < 2.59.5-12.59.5-1

Detection & IOCsextracted from sources · hover to see the quote

  • Detect use of the TIOCLINUX ioctl request from within a snap process; this is the specific syscall+argument combination exploited to inject input into the controlling terminal.
  • Exploitation is only possible when a snap is run on a virtual console (e.g., /dev/tty1–tty6), not under graphical terminal emulators. Scope detection/alerting to processes attached to virtual consoles.
  • Monitor for arbitrary command execution occurring in the terminal session *after* a snap process exits — the injected commands run outside the snap sandbox post-exit, which may appear as orphaned or unexpected shell commands in the parent session.
  • ·Only strict-mode snaps are affected; the sandbox bypass applies specifically to snaps running in strict confinement that are not blocked from issuing TIOCLINUX ioctl calls.
  • ·Graphical terminal emulators (xterm, gnome-terminal, etc.) are NOT affected; exploitation requires the snap to be running on a virtual console.
  • ·Fixed in snapd version 2.59.5-1 on Debian (forky/sid/trixie). Ensure snapd is updated to at least this version to remediate the vulnerability.

CVSS provenance

nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
osv10.0CRITICAL
vendor_debian10.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.