New Ubuntu Flaw Enables Local Attackers to Gain Root Access
ID: 37b52085-4303-560c-9171-36bed675c456
STIX ID: report--37b52085-4303-560c-9171-36bed675c456
Feed Name: Infosecurity Magazine (News)
Executive summary: A timing-based local privilege escalation (CVE-2026-3888) affecting Ubuntu Desktop 24.04+ was disclosed by Qualys; attackers with low-level local access can wait for automated temporary-file cleanup, replace directories with malicious payloads, and cause snap-confine to execute code as root. The issue has a CVSS of 7.8, high exploitation complexity due to required timing, and fixes are available via patched snapd releases; a separate race condition in uutils coreutils (rm) was also identified and remediated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
