ID:9180 - Exploit for Race condition in Snapd - CVE-2021-44731

 
Main Vulnerability Database Exploits ID:9180 - Exploit for Race condition in Snapd - CVE-2021-44731

ID:9180 - Exploit for Race condition in Snapd - CVE-2021-44731

Published: July 10, 2023


Vulnerability identifier: #VU60743
Vulnerability risk: Low
CVE-ID: CVE-2021-44731
CWE-ID: CWE-362
Exploitation vector: Local access
Vulnerable software:
Snapd

Link to public exploit:


Vulnerability description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a race condition in the snap-confine binary when preparing a private mount namespace for a snap.. A local user can  bind-mount their own contents inside the snap's private mount namespace and execute arbitrary code with root privileges.


Remediation

Install updates from vendor's website.