7.8

CVE-2021-44731

Medienbericht
Exploit

snapd could be made to escalate privileges and run programs as administrator

A race condition existed in the snapd 2.54.2 snap-confine binary when preparing a private mount namespace for a snap. This could allow a local attacker to gain root privileges by bind-mounting their own contents inside the snap's private mount namespace and causing snap-confine to execute arbitrary code and hence gain privilege escalation. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Canonical ≫ Snapd Version <= 2.54.2
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 21.10
Fedoraproject ≫ Fedora Version 34
Fedoraproject ≫ Fedora Version 35
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 11.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.94% 0.581
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.1 6
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
NIST 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
Canonical 7.8 1.1 6
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
22.07.2026 20:46
https://ubuntu.com/security/notices/USN-5292-1
Patch
Vendor Advisory
http://www.openwall.com/lists/oss-security/2022/02/18/2
Third Party Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2022/02/23/1
Third Party Advisory
Exploit
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3QTBN7LLZISXIA4KU4UKDR27Q5PXDS2U/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XCGHG6LJAVJJ72TMART6A7N4Z6MSTGI7/
https://www.debian.org/security/2022/dsa-5080
Third Party Advisory
Issue Tracking
http://packetstormsecurity.com/files/170176/snap-confine-must_mkdir_and_open_with_perms-Race-Condition.html
Third Party Advisory
Exploit
VDB Entry
http://seclists.org/fulldisclosure/2022/Dec/4
Third Party Advisory
Exploit
Mailing List
http://www.openwall.com/lists/oss-security/2022/02/23/2
Third Party Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2022/11/30/2
Third Party Advisory
Exploit
Mailing List