Access Control Bypass in Canonical Snapd Affects Applications
CVE-2024-5300

5.6MEDIUM

Key Information:

Vendor
CVE Published:
21 July 2026

What is CVE-2024-5300?

An access control bypass and information disclosure vulnerability in Canonical's snapd allows strictly confined snap applications to access sensitive system user information. This occurs due to improperly configured AppArmor security profile settings, which permit limited snap applications to interact with UNIX domain sockets for information retrieval. When the systemd-userdbd service is operational, it fails to differentiate between confined and unconfined root users, enabling potential exploitation by malicious actors within a snap's restricted environment. Although the issue poses risks, it's mitigated by the fact that systemd-userdbd is not typically installed in standard configurations of Ubuntu.

References

CVSS V3.1

Score:
5.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

James Henstridge
.