New Ubuntu Desktop Vulnerability Turns Local Access Into Root Control
ID: 9ccf11df-537e-5179-8c0b-d0f464b3bdf3
STIX ID: report--9ccf11df-537e-5179-8c0b-d0f464b3bdf3
Feed Name: HackRead
Threat Score
Qualys disclosed CVE-2026-8933, a high-severity local privilege escalation in Ubuntu's snap-confine that lets a local attacker gain root by abusing race conditions during sandbox setup (using a malicious FUSE mount and symlink to write a udev rules file). Affected Ubuntu releases include 22.04, 24.04, 25.10 and 26.04; Canonical has released fixed snapd packages and users are advised to verify snapd versions, install updates and reboot.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
