ID:9180 - Exploit for Race condition in Snapd - CVE-2021-44731
Published: July 10, 2023
Snapd
Link to public exploit:
Vulnerability description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a race condition in the snap-confine binary when preparing a private mount namespace for a snap.. A local user can bind-mount their own contents inside the snap's private mount namespace and execute arbitrary code with root privileges.