CVE-2026-3888: Important Snap Flaw Enables Local Privilege Escalation to Root
ID: f46e2608-1c11-5fb3-bf99-d8453b596c33
STIX ID: report--f46e2608-1c11-5fb3-bf99-d8453b596c33
Feed Name: Qualys Blog
**Executive Summary:** Qualys Threat Research Unit disclosed CVE-2026-3888, a high-severity local privilege escalation in snap-confine combined with systemd-tmpfiles on Ubuntu Desktop (default installs of 24.04 and later) that can allow an unprivileged user to gain root by exploiting a time-based /tmp cleanup window; affected snapd versions and patched releases are listed and immediate upgrades are recommended. The report also notes a separately discovered race condition in the uutils coreutils 'rm' utility that was mitigated before Ubuntu 25.10 release.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
