snapd 2.54.2 fails to perform sufficient validation of snap content interface and layout paths, resulting in the ability for snaps to inject arbitrary AppArmor policy rules via malformed content interface and layout declarations and hence escape strict snap confinement. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1
{ "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.54.3+14.04~esm1", "binary_name": "golang-github-snapcore-snapd-dev" }, { "binary_version": "2.54.3+14.04~esm1", "binary_name": "golang-github-ubuntu-core-snappy-dev" }, { "binary_version": "2.54.3+14.04~esm1", "binary_name": "snap-confine" }, { "binary_version": "2.54.3+14.04~esm1", "binary_name": "snapd" }, { "binary_version": "2.54.3+14.04~esm1", "binary_name": "snapd-dbgsym" }, { "binary_version": "2.54.3+14.04~esm1", "binary_name": "snapd-xdg-open" }, { "binary_version": "2.54.3+14.04~esm1", "binary_name": "ubuntu-core-launcher" }, { "binary_version": "2.54.3+14.04~esm1", "binary_name": "ubuntu-core-snapd-units" }, { "binary_version": "2.54.3+14.04~esm1", "binary_name": "ubuntu-snappy" }, { "binary_version": "2.54.3+14.04~esm1", "binary_name": "ubuntu-snappy-cli" } ] }
{ "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.54.3+16.04~esm2", "binary_name": "golang-github-snapcore-snapd-dev" }, { "binary_version": "2.54.3+16.04~esm2", "binary_name": "golang-github-ubuntu-core-snappy-dev" }, { "binary_version": "2.54.3+16.04~esm2", "binary_name": "snap-confine" }, { "binary_version": "2.54.3+16.04~esm2", "binary_name": "snapd" }, { "binary_version": "2.54.3+16.04~esm2", "binary_name": "snapd-dbgsym" }, { "binary_version": "2.54.3+16.04~esm2", "binary_name": "snapd-xdg-open" }, { "binary_version": "2.54.3+16.04~esm2", "binary_name": "ubuntu-core-launcher" }, { "binary_version": "2.54.3+16.04~esm2", "binary_name": "ubuntu-core-snapd-units" }, { "binary_version": "2.54.3+16.04~esm2", "binary_name": "ubuntu-snappy" }, { "binary_version": "2.54.3+16.04~esm2", "binary_name": "ubuntu-snappy-cli" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.54.3+18.04", "binary_name": "golang-github-snapcore-snapd-dev" }, { "binary_version": "2.54.3+18.04", "binary_name": "golang-github-ubuntu-core-snappy-dev" }, { "binary_version": "2.54.3+18.04", "binary_name": "snap-confine" }, { "binary_version": "2.54.3+18.04", "binary_name": "snapd" }, { "binary_version": "2.54.3+18.04", "binary_name": "snapd-dbgsym" }, { "binary_version": "2.54.3+18.04", "binary_name": "snapd-xdg-open" }, { "binary_version": "2.54.3+18.04", "binary_name": "ubuntu-core-launcher" }, { "binary_version": "2.54.3+18.04", "binary_name": "ubuntu-core-snapd-units" }, { "binary_version": "2.54.3+18.04", "binary_name": "ubuntu-snappy" }, { "binary_version": "2.54.3+18.04", "binary_name": "ubuntu-snappy-cli" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.54.3+20.04", "binary_name": "golang-github-snapcore-snapd-dev" }, { "binary_version": "2.54.3+20.04", "binary_name": "golang-github-ubuntu-core-snappy-dev" }, { "binary_version": "2.54.3+20.04", "binary_name": "snap-confine" }, { "binary_version": "2.54.3+20.04", "binary_name": "snapd" }, { "binary_version": "2.54.3+20.04", "binary_name": "snapd-dbgsym" }, { "binary_version": "2.54.3+20.04", "binary_name": "snapd-xdg-open" }, { "binary_version": "2.54.3+20.04", "binary_name": "ubuntu-core-launcher" }, { "binary_version": "2.54.3+20.04", "binary_name": "ubuntu-core-snapd-units" }, { "binary_version": "2.54.3+20.04", "binary_name": "ubuntu-snappy" }, { "binary_version": "2.54.3+20.04", "binary_name": "ubuntu-snappy-cli" } ] }