Skip to main content

Vendor/product archive

canonical / snapd CVEs

Beta · best-effort

16 CVEs tagged to canonical / snapd3 Critical, 9 High, 3 Medium, 1 Low, 0 Unrated.

CVE-2024-29069

Published Jul 25, 2024

In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap. The snap format is a squashfs file-system image and so c…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-29068

Published Jul 25, 2024

In snapd versions prior to 2.62, snapd failed to properly check the file type when extracting a snap. The snap format is a squashfs file-system image and so can contain files that…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1724

Published Jul 25, 2024

In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict writes to the $HOME/bin path. In Ubuntu, when this path exis…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-27352

Published Jun 21, 2024

When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd will move processes from the con…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-5138

Published May 31, 2024

The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. It was found that snapctl did…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-1523

Published Sep 1, 2023

Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause arbitrary commands to be execute…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-3155

Published Feb 17, 2022

snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local attacker to read information that…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-11933

Published Jul 29, 2020

cloud-init as managed by snapd on Ubuntu Core 16 and Ubuntu Core 18 devices was run without restrictions on every boot, which a physical attacker could exploit by crafting cloud-i…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2019-11503

Published Apr 24, 2019

snap-confine as included in snapd before 2.39 did not guard against symlink races when performing the chdir() to the current working directory of the calling user, aka a "cwd rest…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-11502

Published Apr 24, 2019

snap-confine in snapd before 2.38 incorrectly set the ownership of a snap application to the uid and gid of the first calling user. Consequently, that user had unintended access t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-7304

Published Apr 23, 2019

Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root. This issue affects: Canonical snapd ve…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-7303

Published Apr 23, 2019

A vulnerability in the seccomp filters of Canonical snapd before version 2.37.4 allows a strict mode snap to insert characters into a terminal on a 64-bit host. The seccomp rules…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-16 of 16 CVEsPage 1 of 1