Access Control Bypass in Canonical Snapd Affects Applications
CVE-2024-5300
5.6MEDIUM
Key Information:
- Vendor
- CVE Published:
- 21 July 2026
What is CVE-2024-5300?
An access control bypass and information disclosure vulnerability in Canonical's snapd allows strictly confined snap applications to access sensitive system user information. This occurs due to improperly configured AppArmor security profile settings, which permit limited snap applications to interact with UNIX domain sockets for information retrieval. When the systemd-userdbd service is operational, it fails to differentiate between confined and unconfined root users, enabling potential exploitation by malicious actors within a snap's restricted environment. Although the issue poses risks, it's mitigated by the fact that systemd-userdbd is not typically installed in standard configurations of Ubuntu.
