Headline
Debian Security Advisory 5292-1
Debian Linux Security Advisory 5292-1 - The Qualys Research Team discovered a race condition in the snapd-confine binary which could result in local privilege escalation.
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Debian Security Advisory DSA-5292-1 [email protected]
https://www.debian.org/security/ Moritz Muehlenhoff
December 01, 2022 https://www.debian.org/security/faq
Package : snapd
CVE ID : CVE-2022-3328
The Qualys Research Team discovered a race condition in the snapd-confine
binary which could result in local privilege escalation.
For the stable distribution (bullseye), this problem has been fixed in
version 2.49-1+deb11u2.
We recommend that you upgrade your snapd packages.
For the detailed security status of snapd please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/snapd
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmOI8+AACgkQEMKTtsN8
TjZr3w//QGYaaKqtRpQzsy0cvNSSkZSL5wfnmZM63QLjZ0ilf3xvqI8Qfr440PX1
uXVkrGq1GsfZNJvf7m6A6SpNRNAxuTSIND4JF2oxEq9VXwXCieernAnflpj5xjUq
cv+s0r0t1LsO6TGCesiNyZl2vqcOouEfVZd3EqweXVhyrPZlS1JlJrX9qTAW9noA
4QfMbsQITwVZu9liWeCwXnEkqjZ6oGo9qxkG36+1+BGdCuL1+c2h+zwjOhKm+c5p
1nq7hcEdrxDJWs2jkxoZz7PaVpe52xcFfALuXJ71wjwm7M2v9Is91oMYSmtfp1vs
cgoUxSfsZBlzK+zncjg571S+QHR/OwH6qnAmbol7gGsXgMhAQ9bkqBJQNH8V17h9
+ACUuBz5Y4+9xSLiFuwtycMD3egRp9SPPQ3QoicgiRwL4MZbAPst9sbTafrRV2EL
0rM6b81WhTMtlWHLtNo3urIocU5E/1oK5XY/jxjGnZN1+sgk1W63tG8xBI7ikYo8
9/HL1Oa/1zCeH860aCcbabMVvFnqpaw6KkWZxCT5ty5o6obYO/cv+CVGYLKbp2JX
VUGVb0KyO5ATMhLuPdpgwgimLrn9V2xDmWOtzuNlSwtBDh2fM9X2F0VSv7pdM74j
Qcl459LD3Vz2Oho8LLRIjPLOgZzJbO3g6BqGcEdJj1pYglz65MI=CYJH
-----END PGP SIGNATURE-----
Related news
Race condition in snap-confine's must_mkdir_and_open_with_perms()
Qualys discovered a race condition (CVE-2022-3328) in snap-confine, a SUID-root program installed by default on Ubuntu. In this advisory,they tell the story of this vulnerability (which was introduced in February 2022 by the patch for CVE-2021-44731) and detail how they exploited it in Ubuntu Server (a local privilege escalation, from any user to root) by combining it with two vulnerabilities in multipathd (an authorization bypass and a symlink attack, CVE-2022-41974 and CVE-2022-41973).
The maintainers of the FreeBSD operating system have released updates to remediate a security vulnerability impacting the ping module that could be potentially exploited to crash the program or trigger remote code execution. The issue, assigned the identifier CVE-2022-23093, impacts all supported versions of FreeBSD and concerns a stack-based buffer overflow vulnerability in the ping service. "
Ubuntu Security Notice 5753-1 - The Qualys Research Team discovered that a race condition existed in the snapd snap-confine binary when preparing the private /tmp mount for a snap. A local attacker could possibly use this issue to escalate privileges and execute arbitrary code.