Input Injection Vulnerability in Snapd for Ubuntu
CVE-2023-1523
10CRITICAL
What is CVE-2023-1523?
A vulnerability exists in Snapd where the TIOCLINUX ioctl request could be exploited by a malicious snap. This could lead to unauthorized commands being executed on the controlling terminal after the snap has exited, presenting a potential risk to system integrity. Notably, this issue arises specifically when snaps are operated on virtual consoles; graphical terminal emulators like xterm and gnome-terminal are not affected.
Affected Version(s)
snapd Linux 2.59.5