logo

New Ubuntu Vulnerability Turns System Cleanup into a Root Access Backdoor

ID: cb00717a-f7f2-54f2-80d0-c73e5d15d4c4

STIX ID: report--cb00717a-f7f2-54f2-80d0-c73e5d15d4c4

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-18

Date Updated: 2026-04-23

Author: Ddos

...
...

Qualys disclosed CVE-2026-3888, a local privilege escalation in Ubuntu Desktop (24.04+), where a time-window triggered by systemd-tmpfiles removing /tmp/.snap allows an attacker to recreate that directory with malicious payloads which snap-confine then bind-mounts and executes as root; the issue can lead to full host compromise though exploitation requires waiting (30 days in 24.04, 10 days in later releases). The report also describes a separately mitigated race condition in the uutils coreutils rewrite and recommends checking snapd package versions and applying vendor patches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.