Three New Ubuntu Snap Vulnerabilities Made Public - One Dates Back To Ubuntu 16.04 LTS
([Ubuntu] 4 Hours Ago
Ubuntu Snap Security)
- Reference: 0001647598
- News link: https://www.phoronix.com/news/Ubuntu-Snap-Three-More-Vulns
- Source link:
Canonical today disclosed three new Snap security vulnerabilities affecting snapd. Two are rated high impact vulnerabilities while the third is considered medium but covers all Ubuntu releases of the past decade going back to Ubuntu 16.04 LTS.
CVE-2026-8933 was uncovered by Qualys and allows a local attacker to escalate privileges. CVE-2026-8933 impacts Ubuntu LTS releases going back to 22.04 and is rated high with its CVSS3.1 score.
The other "high" vulnerability is CVE-2026-15226 that allows a local attacker to escape Snap confinement from confined root to unconfined root.
The third one that affects Ubuntu LTS releases back to 16.04 is CVE-2024-5300 and allows sandboxed applications to access hashed user passwords.
More details on these latest Ubuntu Snap security issues can be found via the [1]Ubuntu Discourse .
[1] https://discourse.ubuntu.com/t/snapd-multiple-vulnerabilities-fixed/85433
CVE-2026-8933 was uncovered by Qualys and allows a local attacker to escalate privileges. CVE-2026-8933 impacts Ubuntu LTS releases going back to 22.04 and is rated high with its CVSS3.1 score.
The other "high" vulnerability is CVE-2026-15226 that allows a local attacker to escape Snap confinement from confined root to unconfined root.
The third one that affects Ubuntu LTS releases back to 16.04 is CVE-2024-5300 and allows sandboxed applications to access hashed user passwords.
More details on these latest Ubuntu Snap security issues can be found via the [1]Ubuntu Discourse .
[1] https://discourse.ubuntu.com/t/snapd-multiple-vulnerabilities-fixed/85433