CVE-2026-8933: Local Privilege Escalation in Set-Capabilities snap-confine
ID: da744919-b83b-5502-8183-0b7be3b5ff62
STIX ID: report--da744919-b83b-5502-8183-0b7be3b5ff62
Feed Name: Qualys Blog
Qualys TRU disclosed CVE-2026-8933: a high-severity local privilege escalation in the set-capabilities variant of snap-confine shipped by Ubuntu Desktop 24.04, 25.10, and 26.04. The flaw stems from a race during sandbox initialization that allows an unprivileged user to mount a FUSE filesystem, create symlinks, and widen permissions to cause snap-confine to write to attacker-controlled targets and ultimately gain root (including via systemd-udevd and /run/udev). Canonical has released patches; organizations should apply snapd updates immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
