logo

Ubuntu Desktop Vulnerability Lets Attackers Escalate Privileges to Full Root Access

ID: 1cf4c21e-3fc2-573e-a09b-fb8c42644aa7

STIX ID: report--1cf4c21e-3fc2-573e-a09b-fb8c42644aa7

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-18

Date Updated: 2026-04-22

Author: Divya

...
...

Qualys TRU disclosed CVE-2026-3888, a high-severity local privilege escalation in default Ubuntu Desktop installs where a race between snap-confine and systemd-tmpfiles allows an unprivileged user to recreate /tmp/.snap and have snap-confine bind-mount attacker-controlled files as root, enabling full system compromise; affected snapd and Ubuntu versions and a separate rm/uutils race were documented and mitigations applied.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.