Local root vulnerabilities in the Snap package management toolkit
Qualys has identified two vulnerabilities (CVE-2021-44731, CVE-2021-44730) in the snap-confine utility, shipped with the SUID root flag and called by the snapd process to create an execution environment for applications delivered in self-contained snap packages. The vulnerabilities allow a local unprivileged user to execute code with root privileges on the system. The issues have been fixed in today's snapd package update for Ubuntu 21.10, […]
