Impact
The vulnerability arises in snap-confine, the capability sandbox used by snapd to isolate snap applications. A flaw in the initialization of privilege boundaries when the binary runs with limited ambient capabilities allows a local, non‑root user to bypass the intended restrictions and execute arbitrary code. Successful exploitation elevates the attacker to full root authority, providing complete control over the host.
Affected Systems
Affected releases are Canonical’s Ubuntu 22.04 LTS, 24.04 LTS, and 26.04 LTS. The issue manifests only in versions of snap-confine that are configured to use the set‑capabilities mechanism rather than the default set‑uid‑root installation. Users running snapd on these distributions with the set‑capabilities variant are at risk.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity local privilege escalation. The EPSS score is less than 1 %, suggesting a low probability of exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, the attack requires local access and the possibility of modifying ambient capabilities, so any user who can execute untrusted code or commands on the machine could exploit it. The risk remains significant because the impact is full root access, but the low EPSS implies that immediate detection and patching are prudent.
OpenCVE Enrichment
Ubuntu USN