Cyber Resilience
← All news
Corroborated

Ubuntu snap-confine Vulnerability Enables Local Root Access

Ubuntu fixed a race condition in snap-confine that lets local users escalate to root on default desktop installs. Update snapd now whether you run a few Ubuntu workstations or manage an enterprise fleet; servers without snaps are unaffected.
Sources (5)
What this means for you — CISO:If you run Ubuntu with snapd (Desktop or servers), deploy the latest snapd update on the normal critical cycle. Local root via snap-confine matters on multi-user hosts and anywhere a low-privilege foothold is plausible.
What this means for you — Lean IT orgs:If you use Ubuntu on any desktop or server, install the latest system updates now so snapd is patched. Until then, anyone who can already log in locally may be able to take full control of that machine.
What this means for you — MSP:Inventory clients on Ubuntu with snapd and push the current snapd update across those estates; default Desktop installs are in scope. Confirm patch level before closing the ticket—local root escalations pair badly with any existing low-priv access.
What this means for you — Researcher:Corroborated local root via a snap-confine race on default Ubuntu installs; pull the snapd advisory for affected versions, the race window, and the patch diff.