Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2024-1724

Published: 1 July 2024

In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict writes to the $HOME/bin path. In Ubuntu, when this path exists, it is automatically added to the users PATH. An attacker who could convince a user to install a malicious snap which used the 'home' plug could use this vulnerability to install arbitrary scripts into the users PATH which may then be run by the user outside of the expected snap sandbox and hence allow them to escape confinement.

Notes

Author Note
sarnold
CWE-732
CAPEC-1

Priority

Medium

Cvss 3 Severity Score

6.3

Score breakdown

Status

Package Release Status
snapd
Launchpad, Ubuntu, Debian
bionic Needed

focal
Released (2.63+20.04ubuntu0.1)
jammy
Released (2.63+22.04ubuntu0.1)
mantic Ignored
(end of life, was needed)
noble
Released (2.62+24.04build1)
trusty Ignored
(end of standard support)
upstream
Released (2.62)
xenial Needed

Patches:
upstream: https://github.com/snapcore/snapd/commit/aa191f97713de8dc3ce3ac818539f0b976eb8ef6

Severity score breakdown

Parameter Value
Base score 6.3
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Scope Changed
Confidentiality Low
Integrity impact Low
Availability impact Low
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L