CVE-2026-8933

NameCVE-2026-8933
DescriptionA local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations). Due to a flaw in how privilege boundaries or security sandboxes are initialized when the binary runs under limited ambient capabilities, a local, unprivileged attacker can exploit this behavior to bypass intended restrictions and execute arbitrary code. Successful exploitation allows the local user to elevate their privileges to full root authority.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1142551

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
snapd (PTS)bullseye, bullseye (security)2.49-1+deb11u2vulnerable
bookworm, bookworm (security)2.57.6-1+deb12u1vulnerable
trixie, trixie (security)2.68.3-3+deb13u1vulnerable
forky, sid2.76-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
snapdsource(unstable)(unfixed)1142551

Notes

[trixie] - snapd <ignored> (Not exploitable as snap-confine not yet installed with set capabilities)
https://www.openwall.com/lists/oss-security/2026/07/21/1
https://www.openwall.com/lists/oss-security/2026/07/21/2
Non-suid snap-confine only introduced in debian/2.71-1

Search for package or bug name: Reporting problems