| Name | CVE-2026-8933 |
| Description | A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations). Due to a flaw in how privilege boundaries or security sandboxes are initialized when the binary runs under limited ambient capabilities, a local, unprivileged attacker can exploit this behavior to bypass intended restrictions and execute arbitrary code. Successful exploitation allows the local user to elevate their privileges to full root authority. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| Debian Bugs | 1142551 |
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| snapd (PTS) | bullseye (security), bullseye | 2.49-1+deb11u2 | fixed |
| bookworm, bookworm (security) | 2.57.6-1+deb12u1 | fixed | |
| trixie (security), trixie | 2.68.3-3+deb13u1 | vulnerable | |
| forky, sid | 2.76.3-2 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| snapd | source | bullseye | (not affected) | |||
| snapd | source | bookworm | (not affected) | |||
| snapd | source | (unstable) | 2.76.3-1 | 1142551 |
[trixie] - snapd <ignored> (Not exploitable as snap-confine not yet installed with set capabilities)
[bookworm] - snapd <not-affected> (Only set-capabilities snap-confine is vulnerable; Debian installs it setuid-root and sc_replicate_base_rootfs() is not present)
[bullseye] - snapd <not-affected> (Only set-capabilities snap-confine is vulnerable; Debian installs it setuid-root and sc_replicate_base_rootfs() is not present)
https://www.openwall.com/lists/oss-security/2026/07/21/1
https://www.openwall.com/lists/oss-security/2026/07/21/2
Fixed by: https://github.com/canonical/snapd/commit/cec05b3f0915e3ae5936e923214ce1cb0fb52b3d (2.76.1)
Fixed by: https://github.com/canonical/snapd/commit/cc94fdb321d558362e806d8593b89a29737ac52c (2.76.1)
Non-suid snap-confine only introduced in debian/2.71-1