CVE-2026-3888: Ubuntu Desktop 24.04+ vulnerable to Root exploit
ID: e2fc6e73-69a4-543b-b514-01385eccf73e
STIX ID: report--e2fc6e73-69a4-543b-b514-01385eccf73e
Feed Name: Security Affairs
Qualys researchers disclosed CVE-2026-3888, a high-severity (CVSS 7.8) local privilege escalation affecting default Ubuntu Desktop 24.04+ installations where an attacker can exploit a 10–30 day systemd-tmpfiles cleanup window and snap-confine behavior to mount attacker-controlled files as root and achieve full system compromise; multiple snapd versions are affected and vendors released patches (snapd 2.73+ or later). The advisory also notes a separately fixed race condition in the uutils coreutils rm implementation that could enable privileged file deletion and further escalation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
