Race condition in Snapd - CVE-2021-44731
Published: February 21, 2022 / Updated: July 10, 2023
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a race condition in the snap-confine binary when preparing a private mount namespace for a snap.. A local user can bind-mount their own contents inside the snap's private mount namespace and execute arbitrary code with root privileges.
Affected software
snapd (Debian package)
snapd
snap-confine (Ubuntu package)
snapd (Ubuntu package)
Fedora
Ubuntu
How to mitigate CVE-2021-44731
snapd (Debian package) - addressed in versions 2.37.4-1+deb10u1, 2.49-1+deb11u1
snapd - addressed in versions 2.54.3-1.el7, 2.54.3-1.el8, 2.54.3-1.el9, 2.54.3-1.fc34, 2.54.3-1.fc35
snap-confine (Ubuntu package) - addressed in versions 2.54.3+16.04~esm2, 2.54.3+18.04, 2.54.3+18.04.2ubuntu0.2, 2.54.3+20.04, 2.54.3+20.04.1, 2.54.3+20.04.1ubuntu0.2, 2.54.3+21.10.1, 2.54.3+21.10.1ubuntu0.2
snapd (Ubuntu package) - addressed in versions 2.54.3+16.04~esm2, 2.54.3+18.04, 2.54.3+18.04.2ubuntu0.2, 2.54.3+20.04, 2.54.3+20.04.1, 2.54.3+20.04.1ubuntu0.2, 2.54.3+21.10.1, 2.54.3+21.10.1ubuntu0.2
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Multiple vulnerabilities in snapd
- Debian update for snapd
- Ubuntu update for snapd
- Ubuntu update for snapd
- Ubuntu update for snapd
- Ubuntu update for snapd
- Fedora 34 update for snapd
- Fedora 35 update for snapd
- Fedora EPEL 7 update for snapd
- Fedora EPEL 8 update for snapd
- Fedora EPEL 9 update for snapd