logo

Ubuntu CVE-2026-3888 Bug Lets Attackers Gain Root via systemd Cleanup Timing Exploit

ID: 9d2289a4-10f8-58af-8fbb-4e36cb13a54b

STIX ID: report--9d2289a4-10f8-58af-8fbb-4e36cb13a54b

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2026-03-18

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A high-severity local privilege escalation vulnerability (CVE-2026-3888, CVSS 7.8) affects default Ubuntu Desktop installs (24.04+): by exploiting the interaction between snap-confine and systemd-tmpfiles and leveraging a 10–30 day timing window, an unprivileged local attacker can obtain root access; a separate uutils coreutils race allows symlink-based attacks during root cron runs. Vendor and upstream fixes for snapd and uutils have been released for affected versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.