Race condition in Snapd - CVE-2019-11503
Published: April 30, 2019 / Updated: January 29, 2020
Snapd
Detailed vulnerability description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a race condition when processing symlinks using the chdir() function to restore a working directory. A local user can run snap-confine on a specially crafted symlink and restore files without necessary permissions.