A race condition existed in the snapd 2.54.2 snap-confine binary when preparing a private mount namespace for a snap. This could allow a local attacker to gain root privileges by bind-mounting their own contents inside the snap's private mount namespace and causing snap-confine to execute arbitrary code and hence gain privilege escalation. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1
{
"binaries": [
{
"binary_name": "golang-github-snapcore-snapd-dev",
"binary_version": "2.54.3+14.04~esm1"
},
{
"binary_name": "golang-github-ubuntu-core-snappy-dev",
"binary_version": "2.54.3+14.04~esm1"
},
{
"binary_name": "snap-confine",
"binary_version": "2.54.3+14.04~esm1"
},
{
"binary_name": "snapd",
"binary_version": "2.54.3+14.04~esm1"
},
{
"binary_name": "snapd-xdg-open",
"binary_version": "2.54.3+14.04~esm1"
},
{
"binary_name": "ubuntu-core-launcher",
"binary_version": "2.54.3+14.04~esm1"
},
{
"binary_name": "ubuntu-core-snapd-units",
"binary_version": "2.54.3+14.04~esm1"
},
{
"binary_name": "ubuntu-snappy",
"binary_version": "2.54.3+14.04~esm1"
},
{
"binary_name": "ubuntu-snappy-cli",
"binary_version": "2.54.3+14.04~esm1"
}
],
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}
{
"binaries": [
{
"binary_name": "golang-github-snapcore-snapd-dev",
"binary_version": "2.54.3+16.04~esm2"
},
{
"binary_name": "golang-github-ubuntu-core-snappy-dev",
"binary_version": "2.54.3+16.04~esm2"
},
{
"binary_name": "snap-confine",
"binary_version": "2.54.3+16.04~esm2"
},
{
"binary_name": "snapd",
"binary_version": "2.54.3+16.04~esm2"
},
{
"binary_name": "snapd-xdg-open",
"binary_version": "2.54.3+16.04~esm2"
},
{
"binary_name": "ubuntu-core-launcher",
"binary_version": "2.54.3+16.04~esm2"
},
{
"binary_name": "ubuntu-core-snapd-units",
"binary_version": "2.54.3+16.04~esm2"
},
{
"binary_name": "ubuntu-snappy",
"binary_version": "2.54.3+16.04~esm2"
},
{
"binary_name": "ubuntu-snappy-cli",
"binary_version": "2.54.3+16.04~esm2"
}
],
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}
{
"binaries": [
{
"binary_name": "golang-github-snapcore-snapd-dev",
"binary_version": "2.54.3+18.04"
},
{
"binary_name": "golang-github-ubuntu-core-snappy-dev",
"binary_version": "2.54.3+18.04"
},
{
"binary_name": "snap-confine",
"binary_version": "2.54.3+18.04"
},
{
"binary_name": "snapd",
"binary_version": "2.54.3+18.04"
},
{
"binary_name": "snapd-xdg-open",
"binary_version": "2.54.3+18.04"
},
{
"binary_name": "ubuntu-core-launcher",
"binary_version": "2.54.3+18.04"
},
{
"binary_name": "ubuntu-core-snapd-units",
"binary_version": "2.54.3+18.04"
},
{
"binary_name": "ubuntu-snappy",
"binary_version": "2.54.3+18.04"
},
{
"binary_name": "ubuntu-snappy-cli",
"binary_version": "2.54.3+18.04"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_name": "golang-github-snapcore-snapd-dev",
"binary_version": "2.54.3+20.04.1"
},
{
"binary_name": "golang-github-ubuntu-core-snappy-dev",
"binary_version": "2.54.3+20.04.1"
},
{
"binary_name": "snap-confine",
"binary_version": "2.54.3+20.04.1"
},
{
"binary_name": "snapd",
"binary_version": "2.54.3+20.04.1"
},
{
"binary_name": "snapd-xdg-open",
"binary_version": "2.54.3+20.04.1"
},
{
"binary_name": "ubuntu-core-launcher",
"binary_version": "2.54.3+20.04.1"
},
{
"binary_name": "ubuntu-core-snapd-units",
"binary_version": "2.54.3+20.04.1"
},
{
"binary_name": "ubuntu-snappy",
"binary_version": "2.54.3+20.04.1"
},
{
"binary_name": "ubuntu-snappy-cli",
"binary_version": "2.54.3+20.04.1"
}
],
"availability": "No subscription required"
}