logo

New Ubuntu Flaw Enables Local Attackers to Gain Root Access

ID: 37b52085-4303-560c-9171-36bed675c456

STIX ID: report--37b52085-4303-560c-9171-36bed675c456

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2026-03-18

Date Updated: 2026-04-22

...
...

Executive summary: A timing-based local privilege escalation (CVE-2026-3888) affecting Ubuntu Desktop 24.04+ was disclosed by Qualys; attackers with low-level local access can wait for automated temporary-file cleanup, replace directories with malicious payloads, and cause snap-confine to execute code as root. The issue has a CVSS of 7.8, high exploitation complexity due to required timing, and fixes are available via patched snapd releases; a separate race condition in uutils coreutils (rm) was also identified and remediated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.