VDB

CVE-2021-44730

CVE-2021-44730 PUBLISHED CVSS 6.900000095367432 MEDIUM

snapd 2.54.2 did not properly validate the location of the snap-confine binary. A local attacker who can hardlink this binary to another location to cause snap-confine to execute other arbitrary binaries and hence gain privilege escalation. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1

EPSS 0.35% · 28.0th percentile

Risk Scores

CVSS 2.0
6.900000095367432
EPSS Score
0.35%
28.0th percentile

Affected Products

VendorProductVersions
debiandebian_linux10.0, 11.0
Canonical Ltd.snapd*
canonicalubuntu_linux21.10, 20.04, 18.04
fedoraprojectfedora34, 35
canonicalsnapd0

Timeline

  • Feb 17, 2022 CVE Published
  • Feb 18, 2022 EPSS Score
  • Apr 11, 2022 EPSS Score
  • Jun 3, 2022 EPSS Score
  • Jul 26, 2022 EPSS Score
  • Sep 16, 2022 EPSS Score
  • Nov 7, 2022 EPSS Score
  • Dec 30, 2022 EPSS Score
  • Feb 20, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 13, 2023 EPSS Score
  • Jun 4, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›