Alerts This Week
Warning Icon 1 905
Alerts This Week
Warning Icon 1 905

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 14 articles for you...
87

Debian DSA-6170-1 snapd Local Escalation CVE-2026-3888 Advisory

The Qualys Threat Research Unit (TRU) discovered a local privilege escalation vulnerability in snapd, a daemon and tooling that enable snap packages. Details can be found in the Qualys advisory at https://cdn2.qualys.com/advisory/2026/03/17/snap-confine-systemd-tmpfiles.txt For the oldstable distribution (bookworm), this problem has been fixed. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6170-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso March 19, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : snapd CVE ID : CVE-2026-3888 Debian Bug : 1131120 The Qualys Threat Research Unit (TRU) discovered a local privilege escalation vulnerability in snapd, a daemon and tooling that enable snap packages. Details can be found in the Qualys advisory at https://cdn2.qualys.com/advisory/2026/03/17/snap-confine-systemd-tmpfiles.txt For the oldstable distribution (bookworm), this problem has been fixed in version 2.57.6-1+deb12u1. For the stable distribution (trixie), this problem has been fixed in version 2.68.3-3+deb13u1. We recommend that you upgrade your snapd packages. For the detailed security status of snapd please refer to its security tracker page at: https://security-tracker.debian.org/tracker/snapd Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Local privilege escalation in snapd fixed for Debian with CVE-2026-3888. Upgrade recommended for security.. snapd security,Dedbian advisory,CVE-2026-3888,local privilege escalation. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 19, 2026 Important Debian
172

Ubuntu 24.04 LTS snapd Important Privilege Escalation Fix USN-8102-2

USN-8102-1 introduced a regression in snapd. ========================================================================== Ubuntu Security Notice USN-8102-2 March 17, 2026 snapd regression ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS Summary: USN-8102-1 introduced a regression in snapd Software Description: - snapd: Daemon and tooling that enable snap packages Details: USN-8102-1 fixed a vulnerability in snapd. The update caused a regresision for Ubuntu 24.04 LTS while installing the package. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Qualys discovered that snapd incorrectly handled certain operations in the snap's private /tmp directory. If systemd-tmpfiles is enabled to automatically clean up this directory, a local attacker could possibly use this issue to re-create the deleted directory, resulting in privilege escalation. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS snapd 2.73+ubuntu24.04.2 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8102-2 https://ubuntu.com/security/notices/USN-8102-1 CVE-2026-3888, https://launchpad.net/bugs/2144728 Package Information: https://launchpad.net/ubuntu/+source/snapd/2.73+ubuntu24.04.2 . Ubuntu 24.04 LTS snapd regression fixed. Update required for critical security issue after USN-8102-1.. Ubuntu 24.04 snapd update, snapd privilege escalation fix, security notice, USN-8102-2. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 18, 2026 Important Ubuntu
172

Ubuntu 25.10 Snapd Critical Privilege Escalation USN-8102-1 CVE-2026-3888

snapd could be used to escalate privilege. ========================================================================== Ubuntu Security Notice USN-8102-1 March 17, 2026 snapd vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: snapd could be used to escalate privilege Software Description: - snapd: Daemon and tooling that enable snap packages Details: Qualys discovered that snapd incorrectly handled certain operations in the snap's private /tmp directory. If systemd-tmpfiles is enabled to automatically clean up this directory, a local attacker could possibly use this issue to re-create the deleted directory, resulting in privilege escalation. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 snapd 2.73+ubuntu25.10.1 Ubuntu 24.04 LTS snapd 2.73+ubuntu24.04.1 Ubuntu 22.04 LTS snapd 2.73+ubuntu22.04.1 Ubuntu 20.04 LTS snapd 2.67.1+20.04ubuntu1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS snapd 2.61.4ubuntu0.18.04.1+esm2 Available with Ubuntu Pro Ubuntu 16.04 LTS snapd 2.61.4ubuntu0.16.04.1+esm2 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8102-1 CVE-2026-3888 Package Information: https://launchpad.net/ubuntu/+source/snapd/2.73+ubuntu25.10.1 https://launchpad.net/ubuntu/+source/snapd/2.73+ubuntu24.04.1 https://launchpad.net/ubuntu/+source/snapd/2.73+ubuntu22.04.1 . Snapd is vulnerable toprivilege escalation on multiple Ubuntu versions. Upgrade to avoid security risks.. Ubuntu Snapd Privilege Escalation Security Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 17, 2026 Critical Ubuntu
172

Ubuntu 18.04 LTS & 16.04 LTS: USN-6940-2 critical: snapd issues resolved

Several security issues were fixed in snapd.. ========================================================================== Ubuntu Security Notice USN-6940-2 January 13, 2025 snapd vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in snapd. Software Description: - snapd: Daemon and tooling that enable snap packages Details: USN-6940-1 fixed vulnerabilities in snapd. This update provides the corresponding updates for Ubuntu 18.04 LTS and Ubuntu 16.04 LTS. Original advisory details: Neil McPhail discovered that snapd did not properly restrict writes to the /home/jslarraz/bin path in the AppArmor profile for snaps using the home plug. An attacker who could convince a user to install a malicious snap could use this vulnerability to escape the snap sandbox. (CVE-2024-1724) Zeyad Gouda discovered that snapd failed to properly check the file type when extracting a snap. An attacker who could convince a user to install a malicious snap containing non-regular files could then cause snapd to block indefinitely while trying to read from such files and cause a denial of service. (CVE-2024-29068) Zeyad Gouda discovered that snapd failed to properly check the destination of symbolic links when extracting a snap. An attacker who could convince a user to install a malicious snap containing crafted symbolic links could then cause snapd to write out the contents of the symbolic link destination into a world-readable directory. This in-turn could allow a local unprivileged user to gain access to privileged information. (CVE-2024-29069) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS snapd 2.61.4ubuntu0.18.04.1+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS snapd 2.61.4ubuntu0.16.04.1+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6940-2 https://ubuntu.com/security/notices/USN-6940-1 CVE-2024-1724, CVE-2024-29068, CVE-2024-29069 . The recent brief covers essential safety enhancements for snapd in Ubuntu, addressing significant vulnerabilities that threaten overall system stability.. snapd updates, Ubuntu security, software vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 13, 2025 Critical Ubuntu
172

Ubuntu 24.04 LTS Snapd: USN-6940-1 Critical Security Advisory

Several security issues were fixed in snapd.. ========================================================================== Ubuntu Security Notice USN-6940-1 August 01, 2024 snapd vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in snapd. Software Description: - snapd: Daemon and tooling that enable snap packages Details: Neil McPhail discovered that snapd did not properly restrict writes to the $HOME/bin path in the AppArmor profile for snaps using the home plug. An attacker who could convince a user to install a malicious snap could use this vulnerability to escape the snap sandbox. (CVE-2024-1724) Zeyad Gouda discovered that snapd failed to properly check the file type when extracting a snap. An attacker who could convince a user to install a malicious snap containing non-regular files could then cause snapd to block indefinitely while trying to read from such files and cause a denial of service. (CVE-2024-29068) Zeyad Gouda discovered that snapd failed to properly check the destination of symbolic links when extracting a snap. An attacker who could convince a user to install a malicious snap containing crafted symbolic links could then cause snapd to write out the contents of the symbolic link destination into a world-readable directory. This in-turn could allow a local unprivileged user to gain access to privileged information. (CVE-2024-29069) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS snapd 2.63+24.04ubuntu0.1 Ubuntu 22.04 LTS snapd 2.63+22.04ubuntu0.1 Ubuntu 20.04 LTS snapd 2.63+20.04ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6940-1 CVE-2024-1724, CVE-2024-29068, CVE-2024-29069 Package Information: https://launchpad.net/ubuntu/+source/snapd/2.63+24.04ubuntu0.1 https://launchpad.net/ubuntu/+source/snapd/2.63+22.04ubuntu0.1 https://launchpad.net/ubuntu/+source/snapd/2.63+20.04ubuntu0.1 . Important revisions for snapd in Ubuntu address several vulnerabilities. Upgrade your system to maintain security.. snapd security updates, Ubuntu system security, updates for snap packages. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 01, 2024 Critical Ubuntu
172

Ubuntu 23.04 USN-6125-1 Urgent: Snapd Access Vulnerability Warning

An intended access restriction in snapd could be bypassed by strict mode snaps.. =========================================================================Ubuntu Security Notice USN-6125-1 May 31, 2023 snapd vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.04 - Ubuntu 22.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS (Available with Ubuntu Pro) Summary: An intended access restriction in snapd could be bypassed by strict mode snaps. Software Description: - snapd: Daemon and tooling that enable snap packages Details: It was discovered that the snap sandbox did not restrict the use of the ioctl system call with a TIOCLINUX request. This could be exploited by a malicious snap to inject commands into the controlling terminal which would then be executed outside of the snap sandbox once the snap had exited. This could allow an attacker to execute arbitrary commands outside of the confined snap sandbox. Note: graphical terminal emulators like xterm, gnome-terminal and others are not affected - this can only be exploited when snaps are run on a virtual console. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.04: snapd 2.59.1+23.04ubuntu1.1 Ubuntu 22.10: snapd 2.58+22.10.1 Ubuntu 22.04 LTS: snapd 2.58+22.04.1 Ubuntu 20.04 LTS: snapd 2.58+20.04.1 Ubuntu 18.04 LTS: snapd 2.58+18.04.1 Ubuntu 16.04 LTS (Available with Ubuntu Pro): snapd 2.54.3+16.04.0ubuntu0.1~esm6 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6125-1 CVE-2023-1523 Package Information: https://launchpad.net/ubuntu/+source/snapd/2.59.1+23.04ubuntu1.1 https://launchpad.net/ubuntu/+source/snapd/2.58+22.10.1 https://launchpad.net/ubuntu/+source/snapd/2.58+22.04.1 https://launchpad.net/ubuntu/+source/snapd/2.58+20.04.1 https://launchpad.net/ubuntu/+source/snapd/2.58+18.04.1 . Perform an update on your Ubuntu installation to mitigate the snapd security flaw impacting various versions and avoid potential command execution risks.. Snapd Security Update, Ubuntu System Patching, Command Injection Prevention. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 31, 2023 Critical Ubuntu
87

Debian Bullseye DSA-5292-1 Moderate Snapd Local Escalation Fix

The Qualys Research Team discovered a race condition in the snapd-confine binary which could result in local privilege escalation. For the stable distribution (bullseye), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5292-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff December 01, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : snapd CVE ID : CVE-2022-3328 The Qualys Research Team discovered a race condition in the snapd-confine binary which could result in local privilege escalation. For the stable distribution (bullseye), this problem has been fixed in version 2.49-1+deb11u2. We recommend that you upgrade your snapd packages. For the detailed security status of snapd please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/snapd Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical vulnerability in snapd addressed in Debian advisory DSA-5292-1. Users of stable systems should apply the recommended update.. Snapd Security Update, Debian DSA-5292-1, Local Privilege Escalation. . LinuxSecurity.com Team

Calendar%202 Dec 01, 2022 Debian
172

Ubuntu 22.10: USN-5753-1 Moderate Snapd Privilege Escalation

snapd could be made to run programs as an administrator.. =========================================================================Ubuntu Security Notice USN-5753-1 December 01, 2022 snapd vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 ESM Summary: snapd could be made to run programs as an administrator. Software Description: - snapd: Daemon and tooling that enable snap packages Details: The Qualys Research Team discovered that a race condition existed in the snapd snap-confine binary when preparing the private /tmp mount for a snap. A local attacker could possibly use this issue to escalate privileges and execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.10: snapd 2.57.5+22.10ubuntu0.1 Ubuntu 22.04 LTS: snapd 2.57.5+22.04ubuntu0.1 Ubuntu 20.04 LTS: snapd 2.57.5+20.04ubuntu0.1 Ubuntu 18.04 LTS: snapd 2.57.5+18.04ubuntu0.1 Ubuntu 16.04 ESM: snapd 2.54.3+16.04.0ubuntu0.1~esm5 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5753-1 CVE-2022-3328 Package Information: https://launchpad.net/ubuntu/+source/snapd/2.57.5+22.10ubuntu0.1 https://launchpad.net/ubuntu/+source/snapd/2.57.5+22.04ubuntu0.1 https://launchpad.net/ubuntu/+source/snapd/2.57.5+20.04ubuntu0.1 https://launchpad.net/ubuntu/+source/snapd/2.57.5+18.04ubuntu0.1 . Ubuntu Security Notice USN-5754-1 highlights a vulnerability in snapd that could enable local users to gain higher privileges. Immediate update is advised.. snapd, Privilege Escalation, Ubuntu Security, Local Attack. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 01, 2022 Important Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here