Canonical today disclosed three new Snap security vulnerabilities affecting snapd. Two are rated high impact vulnerabilities while the third is considered medium but covers all Ubuntu releases of the past decade going back to Ubuntu 16.04 LTS. CVE-2026-8933 was uncovered by Qualys and allows a local attacker to escalate privileges. CVE-2026-8933 impacts Ubuntu LTS releases going back to 22.04 and is rated high with its CVSS3.1 score. The other "high" vulnerability is CVE-2026-15226 that allows a local attacker to escape Snap confinement from confined root to unconfined root. The third one that affects Ubuntu LTS releases back to 16.04 is CVE-2024-5300 and allows sandboxed applications to access hashed user passwords. More details on these latest Ubuntu Snap security issues can be found via the Ubuntu Discourse.
Three New Ubuntu Snap Vulnerabilities Made Public - One Dates Back To Ubuntu 16.04 LTS
Full Article
Original Source
Read the full article at Phoronix →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.