---
title: "CVE-2017-10600\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2017-10600?format=md
keywords: index, follow
---

# CVE-2017-10600

Publication date 11 July 2017

Last updated 25 August 2025

---

Ubuntu priority

**High**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**5.9 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2017-10600?format=md#impact-score)

Toggle side navigation

## Description

ubuntu-image 1.0 before 2017-07-07, when invoked as non-root, creates files
in the resulting image with the uid of the invoking user. When the
resulting image is booted, a local attacker with the same uid as the image
creator has unintended access to cloud-init and snapd directories.

### From the Ubuntu Security Team

ubuntu-image 1.0 when invoked as non-root on systems with e2fsprogs >= 1.43
creates file permissions in the resulting image with the UID of the invoking
user. When the resulting image is booted, a local attacker with the same UID
as the image creator can alter installed snap packages and signatures to
downgrade or potentially replace snap packages.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2017-10600?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| ubuntu-image | 17.04 zesty | Fixed 1.0+17.04ubuntu1.1 |
| 16.10 yakkety | Fixed 1.0+16.10ubuntu1.1 |
| 16.04 LTS xenial | Ignored |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2017-10600?format=md#patch-details)

## Notes

---

### [jdstrand](https://launchpad.net/~jdstrand)

this issue only affects Ubuntu Core and not snapd on Ubuntu classic
while snapd is not affected, an updated snapd will attempt to
correct permissions on refresh. Because this only affects Ubuntu Core, that
update will happen via the snap store and not included as a separate security
update for the Ubuntu archive.
Ubuntu 16.04 LTS has e2fsprogs 1.42.13

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| ubuntu-image | * Upstream:   <https://github.com/CanonicalLtd/ubuntu-image/pull/135> |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

5.9 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | Low |
  | Integrity impact | Low |
  | Availability impact | Low |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 5.9 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-10600)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2017-10600)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2017-10600)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2017-10600)

### Other references

* <https://github.com/CanonicalLtd/ubuntu-image/pull/135>
* <https://forum.snapcraft.io/t/ownership-bug-in-ubuntu-image/1285/1>
* <https://www.cve.org/CVERecord?id=CVE-2017-10600>
