logo

Ubuntu snap-confine Flaw Lets Any Local User Gain Full Root Access

ID: 40c164cf-bca6-5421-834c-b968f8f00b5c

STIX ID: report--40c164cf-bca6-5421-834c-b968f8f00b5c

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

Author: Tamilselvan

...
...

A high-severity local privilege escalation (CVE-2026-8933) was disclosed in Ubuntu's snap-confine where a shift from setuid-root to set-capabilities introduced a race condition that allows an unprivileged local user to cause snap-confine to create arbitrary root-owned files and chain that to systemd-udevd to execute commands as root; Qualys produced an end-to-end PoC on Ubuntu 24.04 and 26.04. The report lists affected releases, fixed snapd versions (2.76.1 / equivalent packages), a related kernel ptrace timing issue (CVE-2026-46333), mitigation guidance, and a disclosure timeline.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.