Particle.news

Race-Condition Bug in snap-confine Lets Local Users Gain Root on Ubuntu Desktop

Canonical issued fixes after Qualys published a technical analysis and proof‑of‑concept, making rapid patching and asset checks critical.

Overview

  • Qualys disclosed CVE-2026-8933 on July 21, describing a high-severity local privilege escalation in snap-confine that can give an unprivileged local user full root access on default Ubuntu Desktop installs.
  • The flaw stems from a hardening change that moved snap-confine from setuid-root to a set-capabilities model and left a brief window where temporary files in /tmp remained under the caller's control.
  • Exploitation uses two concurrent race conditions: mounting a malicious FUSE filesystem over a scratch directory and following a symlink while widening permissions so snap-confine writes a malicious udev rules file that systemd-udevd executes as root.
  • Canonical and the Ubuntu Security Team have released patched snapd packages for supported releases and advise administrators to verify snapd versions, apply updates, and reboot affected machines.
  • The exploit requires local command execution but can turn limited footholds from phishing, stolen credentials, or other bugs into full host compromise, so organizations should inventory endpoints, prioritize updates, and upgrade or isolate out-of-support releases such as Ubuntu 25.10.