← Back

CVE-2021-4120

nvd nist
Published: Feb 17, 2022Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

snapd 2.54.2 fails to perform sufficient validation of snap content interface and layout paths, resulting in the ability for snaps to inject arbitrary AppArmor policy rules via malformed content interface and layout declarations and hence escape strict snap confinement. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1

Affected (6)

2 products
Snapd
Ubuntu Linux
1 product
Fedora
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.54.2
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 18.04
Version 20.04
Version 21.10
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 34
Version 35

References (10)

Source: security@ubuntu.com
ExploitMailing ListThird Party Advisory
Source: security@ubuntu.com
ExploitIssue TrackingThird Party Advisory
Source: security@ubuntu.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.