CVE-2024-29069
published 2024-07-25CVE-2024-29069: In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap. The snap format is a squashfs…
PriorityP338high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
EPSS
0.23%
13.6th percentile
In snapd versions prior to 2.62, snapd failed to properly check the
destination of symbolic links when extracting a snap. The snap format
is a squashfs file-system image and so can contain symbolic links and
other file types. Various file entries within the snap squashfs image
(such as icons and desktop files etc) are directly read by snapd when
it is extracted. An attacker who could convince a user to install a
malicious snap which contained symbolic links at these paths could then
cause snapd to write out the contents of the symbolic link destination
into a world-readable directory. This in-turn could allow an unprivileged
user to gain access to privileged information.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | snapd | < 2.62 | 2.62 |
| debian | snapd | < snapd 2.62-1 (forky) | snapd 2.62-1 (forky) |
| github.com | snapcore_snapd | >= 0 < 2.62 | 2.62 |
| snapcraft | snapd | >= 0 < 2.62-1 | 2.62-1 |
| snapcraft | snapd | >= 0 < 2.62-1 | 2.62-1 |
| snapcraft | snapd | >= 0 < 2.63+20.04ubuntu0.1 | 2.63+20.04ubuntu0.1 |
| snapcraft | snapd | >= 0 < 2.63+22.04ubuntu0.1 | 2.63+22.04ubuntu0.1 |
| snapcraft | snapd | >= 0 < 2.63+24.04ubuntu0.1 | 2.63+24.04ubuntu0.1 |
| snapcraft | snapd | >= 0 < 2.61.4ubuntu0.16.04.1+esm1 | 2.61.4ubuntu0.16.04.1+esm1 |
| snapcraft | snapd | >= 0 < 2.61.4ubuntu0.18.04.1+esm1 | 2.61.4ubuntu0.18.04.1+esm1 |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
osv8.2HIGH
vendor_ubuntu6.3MEDIUM
vendor_debian4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
snapd vulnerabilities
osv·2025-01-13·CVSS 8.2
CVE-2024-1724 [HIGH] snapd vulnerabilities
snapd vulnerabilities
USN-6940-1 fixed vulnerabilities in snapd. This update provides the
corresponding updates for Ubuntu 18.04 LTS and Ubuntu 16.04 LTS.
Original advisory details:
Neil McPhail discovered that snapd did not properly restrict writes to
the /home/jslarraz/bin path in the AppArmor profile for snaps using the home
plug. An attacker who could convince a user to install a malicious snap
could use this vulnerability to escape the snap sandbox. (CVE-2024-1724)
Zeyad Gouda discovered that snapd failed to properly check the file type
when extracting a snap. An attacker who could convince a user to install
a malicious snap containing non-regular files could then cause snapd to
block indefinitely while trying to read from such files and cause a
denial of service. (CVE-2024-29068)
OSV
snapd failed to properly check the destination of symbolic links when extracting a snap in github.com/snapcore/snapd
osv·2024-08-06
CVE-2024-29069 snapd failed to properly check the destination of symbolic links when extracting a snap in github.com/snapcore/snapd
snapd failed to properly check the destination of symbolic links when extracting a snap in github.com/snapcore/snapd
snapd failed to properly check the destination of symbolic links when extracting a snap in github.com/snapcore/snapd.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/snapcore/snapd before v2.62.0.
OSV
snapd vulnerabilities
osv·2024-08-01·CVSS 8.2
CVE-2024-1724 [HIGH] snapd vulnerabilities
snapd vulnerabilities
Neil McPhail discovered that snapd did not properly restrict writes to the
$HOME/bin path in the AppArmor profile for snaps using the home plug. An
attacker who could convince a user to install a malicious snap could use this
vulnerability to escape the snap sandbox. (CVE-2024-1724)
Zeyad Gouda discovered that snapd failed to properly check the file type when
extracting a snap. An attacker who could convince a user to install a malicious
snap containing non-regular files could then cause snapd to block indefinitely
while trying to read from such files and cause a denial of
service. (CVE-2024-29068)
Zeyad Gouda discovered that snapd failed to properly check the destination of
symbolic links when extracting a snap. An attacker who could convince a user to
install a m
OSV
CVE-2024-29069: In snapd versions prior to 2
osv·2024-07-25·CVSS 7.3
CVE-2024-29069 [HIGH] CVE-2024-29069: In snapd versions prior to 2
In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap. The snap format is a squashfs file-system image and so can contain symbolic links and other file types. Various file entries within the snap squashfs image (such as icons and desktop files etc) are directly read by snapd when it is extracted. An attacker who could convince a user to install a malicious snap which contained symbolic links at these paths could then cause snapd to write out the contents of the symbolic link destination into a world-readable directory. This in-turn could allow an unprivileged user to gain access to privileged information.
GHSA
snapd failed to properly check the destination of symbolic links when extracting a snap
ghsa·2024-07-25
CVE-2024-29069 [LOW] CWE-59 snapd failed to properly check the destination of symbolic links when extracting a snap
snapd failed to properly check the destination of symbolic links when extracting a snap
In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap. The snap format is a squashfs file-system image and so can contain symbolic links and other file types. Various file entries within the snap squashfs image (such as icons and desktop files etc) are directly read by snapd when it is extracted. An attacker who could convince a user to install a malicious snap which contained symbolic links at these paths could then cause snapd to write out the contents of the symbolic link destination into a world-readable directory. This in-turn could allow an unprivileged user to gain access to privileged information.
OSV
snapd failed to properly check the destination of symbolic links when extracting a snap
osv·2024-07-25
CVE-2024-29069 [LOW] snapd failed to properly check the destination of symbolic links when extracting a snap
snapd failed to properly check the destination of symbolic links when extracting a snap
In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap. The snap format is a squashfs file-system image and so can contain symbolic links and other file types. Various file entries within the snap squashfs image (such as icons and desktop files etc) are directly read by snapd when it is extracted. An attacker who could convince a user to install a malicious snap which contained symbolic links at these paths could then cause snapd to write out the contents of the symbolic link destination into a world-readable directory. This in-turn could allow an unprivileged user to gain access to privileged information.
Ubuntu
snapd vulnerabilities
vendor_ubuntu·2025-01-13·CVSS 6.3
CVE-2024-29068 [MEDIUM] snapd vulnerabilities
Title: snapd vulnerabilities
Summary: Several security issues were fixed in snapd.
USN-6940-1 fixed vulnerabilities in snapd. This update provides the
corresponding updates for Ubuntu 18.04 LTS and Ubuntu 16.04 LTS.
Original advisory details:
Neil McPhail discovered that snapd did not properly restrict writes to
the /home/jslarraz/bin path in the AppArmor profile for snaps using the home
plug. An attacker who could convince a user to install a malicious snap
could use this vulnerability to escape the snap sandbox. (CVE-2024-1724)
Zeyad Gouda discovered that snapd failed to properly check the file type
when extracting a snap. An attacker who could convince a user to install
a malicious snap containing non-regular files could then cause snapd to
block indefinitely while trying to read f
Ubuntu
snapd vulnerabilities
vendor_ubuntu·2024-08-01·CVSS 6.3
CVE-2024-1724 [MEDIUM] snapd vulnerabilities
Title: snapd vulnerabilities
Summary: Several security issues were fixed in snapd.
Neil McPhail discovered that snapd did not properly restrict writes to the
$HOME/bin path in the AppArmor profile for snaps using the home plug. An
attacker who could convince a user to install a malicious snap could use this
vulnerability to escape the snap sandbox. (CVE-2024-1724)
Zeyad Gouda discovered that snapd failed to properly check the file type when
extracting a snap. An attacker who could convince a user to install a malicious
snap containing non-regular files could then cause snapd to block indefinitely
while trying to read from such files and cause a denial of
service. (CVE-2024-29068)
Zeyad Gouda discovered that snapd failed to properly check the destination of
symbolic links when extractin
Debian
CVE-2024-29069: snapd - In snapd versions prior to 2.62, snapd failed to properly check the destination ...
vendor_debian·2024·CVSS 4.8
CVE-2024-29069 [MEDIUM] CVE-2024-29069: snapd - In snapd versions prior to 2.62, snapd failed to properly check the destination ...
In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap. The snap format is a squashfs file-system image and so can contain symbolic links and other file types. Various file entries within the snap squashfs image (such as icons and desktop files etc) are directly read by snapd when it is extracted. An attacker who could convince a user to install a malicious snap which contained symbolic links at these paths could then cause snapd to write out the contents of the symbolic link destination into a world-readable directory. This in-turn could allow an unprivileged user to gain access to privileged information.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.62-1)
sid: resolved (fixed in 2.62-1)
trixie: res
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-07-25
Published