USN-8579-1: snapd vulnerabilities
James Henstridge discovered that snapd's default apparmor template did not restrict access to systemd-userdbd varlink interface. A local attacker could possibly use this issue to obtain sensitive information. (CVE-2024-5300) Qualys discovered that snap-confine can be tricked to create attacker-controlled files at certain privileged locations. A local attacker could possibly use this issue to bypass intended restrictions and escalate privileges to root. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-8933) Zygmunt Krynicki discovered that snapd's default seccomp template did not restrict the creation of executables with the set-user-ID attribute. A local attacker could possibly use this issue to create and execute setuid binaries. (CVE-2026-15226)
CSIRTS triage
- What
- Multiple vulnerabilities could allow local attackers to obtain sensitive information or escalate privileges.
- Who is affected
- Users of snapd on Ubuntu 22.04 LTS, 24.04 LTS, and 26.04 LTS.
- Urgency
- Remediation is important due to the potential for information disclosure and privilege escalation.
- Action
- Update snapd to the latest version to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch snapd
Get an email when a new snapd advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://ubuntu.com/security/notices/USN-8579-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2024-53000.10% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all scored CVEs.
- Low exploitation riskCVE-2026-89330.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all scored CVEs.
- Low exploitation riskCVE-2026-152260.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2024-5300 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-8933 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15226 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] snapd: Multiple Vulnerabilitiescert-bund
- highCVE-2026-8933: A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core comp…nvd
- highCVE-2026-15226: A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execu…nvd
- mediumCVE-2024-5300: An access control bypass and information disclosure vulnerability exists in the base AppArmor s…nvd
More from Ubuntu Security Notices
- highUSN-8620-4: Linux kernel (Intel IoTG) vulnerabilities2026-07-31
- highUSN-8620-3: Linux kernel (Intel IoTG) vulnerabilities2026-07-31
- unknownUSN-8625-1: OpenSSL vulnerability2026-07-30
- unknownUSN-8624-1: Sinatra vulnerability2026-07-29
- unknownUSN-8623-1: Linux kernel (NVIDIA) vulnerabilities2026-07-29