CVE-2024-5138
published 2024-05-31CVE-2024-5138: The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. It was…
PriorityP346high8.1CVSS 3.1
AVNACLPRLUINSUCNIHAH
EPSS
0.83%
53.3th percentile
The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. It was found that snapctl did not properly parse command-line arguments, allowing an unprivileged user to trigger an authorised action on behalf of the snap that would normally require administrator privileges to perform. This could possibly allow an unprivileged user to perform a denial of service or similar.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | snapd | >= 2.51.6 < 2.63.1 | 2.63.1 |
| canonical_ltd | snapd | < 68ee9c6aa916ab87dbfd9a26030690f2cabf1e14 | 68ee9c6aa916ab87dbfd9a26030690f2cabf1e14 |
| debian | snapd | < snapd 2.62-3 (forky) | snapd 2.62-3 (forky) |
| github.com | snapcore_snapd | >= 0 < 0.0.0-20240524114846-68ee9c6aa916 | 0.0.0-20240524114846-68ee9c6aa916 |
| github.com | snapcore_snapd | >= 2.51.6 < 2.63.1 | 2.63.1 |
| snapcraft | snapd | >= 0 < 2.62-3 | 2.62-3 |
| snapcraft | snapd | >= 0 < 2.62-3 | 2.62-3 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
ghsa8.1HIGH
osv8.1HIGH
vendor_debian8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2024-5138: snapd snapctl auth bypass
osv·2025-01-16·CVSS 8.1
CVE-2024-5138 [HIGH] CVE-2024-5138: snapd snapctl auth bypass
CVE-2024-5138: snapd snapctl auth bypass
### Impact
A snap with prior permissions to create a mount entry on the host, such as firefox, normally uses the permission from one of the per-snap hook programs. A unprivileged users cannot normally trigger that behaviour by using `snap run --shell firefox` followed by `snapctl mount`, since snapd validates the requesting user identity (root or non-root). The issue allows unprivileged users to bypass that check by crafting a malicious command line vector which confuses snapd into thinking the help message is requested.
Unprivileged user on a default installation of Ubuntu, where firefox is as provided as a snap, may cause a denial-of-service attack by repeatedly mounting hunspell database over and over and eventually exhausting system memory.
GHSA
CVE-2024-5138: snapd snapctl auth bypass
ghsa·2025-01-16·CVSS 8.1
CVE-2024-5138 [HIGH] CWE-285 CVE-2024-5138: snapd snapctl auth bypass
CVE-2024-5138: snapd snapctl auth bypass
### Impact
A snap with prior permissions to create a mount entry on the host, such as firefox, normally uses the permission from one of the per-snap hook programs. A unprivileged users cannot normally trigger that behaviour by using `snap run --shell firefox` followed by `snapctl mount`, since snapd validates the requesting user identity (root or non-root). The issue allows unprivileged users to bypass that check by crafting a malicious command line vector which confuses snapd into thinking the help message is requested.
Unprivileged user on a default installation of Ubuntu, where firefox is as provided as a snap, may cause a denial-of-service attack by repeatedly mounting hunspell database over and over and eventually exhausting system memory.
OSV
CVE-2024-5138 in github.com/snapcore/snapd
osv·2024-06-14·CVSS 8.1
CVE-2024-5138 [HIGH] CVE-2024-5138 in github.com/snapcore/snapd
CVE-2024-5138 in github.com/snapcore/snapd
CVE-2024-5138 in github.com/snapcore/snapd
OSV
Duplicate Advisory: CVE-2024-5138: snapd snapctl auth bypass
osv·2024-05-31·CVSS 8.1
CVE-2024-5138 [HIGH] Duplicate Advisory: CVE-2024-5138: snapd snapctl auth bypass
Duplicate Advisory: CVE-2024-5138: snapd snapctl auth bypass
# Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-p9v8-q5m4-pf46. This link is maintained to preserve external references.
# Original Description
The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. It was found that snapctl did not properly parse command-line arguments, allowing an unprivileged user to trigger an authorised action on behalf of the snap that would normally require administrator privileges to perform. This could possibly allow an unprivileged user to perform a denial of service or similar.
GHSA
Duplicate Advisory: CVE-2024-5138: snapd snapctl auth bypass
ghsa·2024-05-31·CVSS 8.1
CVE-2024-5138 [HIGH] Duplicate Advisory: CVE-2024-5138: snapd snapctl auth bypass
Duplicate Advisory: CVE-2024-5138: snapd snapctl auth bypass
# Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-p9v8-q5m4-pf46. This link is maintained to preserve external references.
# Original Description
The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. It was found that snapctl did not properly parse command-line arguments, allowing an unprivileged user to trigger an authorised action on behalf of the snap that would normally require administrator privileges to perform. This could possibly allow an unprivileged user to perform a denial of service or similar.
OSV
CVE-2024-5138: The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap
osv·2024-05-31·CVSS 8.1
CVE-2024-5138 [HIGH] CVE-2024-5138: The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap
The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. It was found that snapctl did not properly parse command-line arguments, allowing an unprivileged user to trigger an authorised action on behalf of the snap that would normally require administrator privileges to perform. This could possibly allow an unprivileged user to perform a denial of service or similar.
Debian
CVE-2024-5138: snapd - The snapctl component within snapd allows a confined snap to interact with the s...
vendor_debian·2024·CVSS 8.1
CVE-2024-5138 [HIGH] CVE-2024-5138: snapd - The snapctl component within snapd allows a confined snap to interact with the s...
The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. It was found that snapctl did not properly parse command-line arguments, allowing an unprivileged user to trigger an authorised action on behalf of the snap that would normally require administrator privileges to perform. This could possibly allow an unprivileged user to perform a denial of service or similar.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.62-3)
sid: resolved (fixed in 2.62-3)
trixie: resolved (fixed in 2.62-3)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.launchpad.net/snapd/+bug/2065077https://github.com/snapcore/snapd/commit/68ee9c6aa916ab87dbfd9a26030690f2cabf1e14https://github.com/snapcore/snapd/security/advisories/GHSA-p9v8-q5m4-pf46https://www.cve.org/CVERecord?id=CVE-2024-5138https://bugs.launchpad.net/snapd/+bug/2065077https://github.com/snapcore/snapd/commit/68ee9c6aa916ab87dbfd9a26030690f2cabf1e14https://github.com/snapcore/snapd/security/advisories/GHSA-p9v8-q5m4-pf46https://www.cve.org/CVERecord?id=CVE-2024-5138
2024-05-31
Published