ZeroHour
Security Affairspublished ()ingested @securityaffairs

CVE-2021-44731 Linux privilege escalation bug affects Canonical's Snap Package Manager

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-3996
+1 in the same advisory: …3995
A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem.

A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vulnerable system to unmount other users' filesystems that are either world-writable themselves (like /tmp) or mounted in a world-writable directory. An attacker may use this flaw to cause a denial of service to applications that use the affected filesystems.

NVD description · AI analysis pending
5.5<1% PoC
  • kernel util-linux
  • kernel fedora
CVE-2021-3997
A flaw was found in systemd.

A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp.

NVD description · AI analysis pending
5.52% PoC
  • systemd project systemd
  • systemd project fedora
  • systemd project enterprise linux
CVE-2021-3999
+1 in the same advisory: …3998
A flaw was found in glibc.

A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can control the input buffer and size passed to getcwd() in a setuid program could use this flaw to potentially execute arbitrary code and escalate their privileges on the system.

NVD description · AI analysis pending
7.8
group max
<1% PoC
  • gnu glibc
  • gnu debian linux
  • gnu e-series performance analyzer
  • +1 more
CVE-2021-44730
+1 in the same advisory: …44731
snapd 2.54.2 did not properly validate the location of the snap-confine binary.

snapd 2.54.2 did not properly validate the location of the snap-confine binary. A local attacker who can hardlink this binary to another location to cause snap-confine to execute other arbitrary binaries and hence gain privilege escalation. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1

NVD description · AI analysis pending
8.8
group max
<1%
  • canonical snapd
  • canonical ubuntu linux
  • canonical fedora
  • +1 more
Full article293 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini February 18, 2022

Qualys experts found a new Linux privilege escalation vulnerability, tracked as CVE-2021-44731, in Canonical’s Snap Package Manager.

Canonical’s Snap software packaging and deployment system are affected by multiple vulnerabilities, including a privilege escalation flaw tracked as CVE-2021-44731 (CVSS score 7.8).

Snap is a software packaging and deployment system developed by Canonical for operating systems that use the Linux kernel. The packages, called snaps, and the tool for using them, snapd, work across a range of Linux distributions

The flaws have been discovered by Qualys researchers, the CVE-2021-44731 is the most severe one and is a race condition in the snap-confine’s setup_private_mount() function.

The snap-confine is a program used internally by snapd to construct the execution environment for snap applications. An unprivileged user can trigger the flaw to gain root privileges on the affected host.

“Successful exploitation of this vulnerability allows any unprivileged user to gain root privileges on the vulnerable host.” reads the post published by the experts. “As soon as the Qualys Research Team confirmed the vulnerability, we engaged in responsible vulnerability disclosure and coordinated with both vendor and open-source distributions in announcing this newly discovered vulnerability.”

Qualys experts also developed a PoC exploit for this issue that allows obtaining full root privileges on default Ubuntu installations.

Below is the full list of vulnerabilities discovered by the experts:

CVEDescription
CVE-2021-44731Race condition in snap-confine’s setup_private_mount()
CVE-2021-44730Hardlink attack in snap-confine’s sc_open_snapd_tool()
CVE-2021-3996Unauthorized unmount in util-linux’s libmount
CVE-2021-3995Unauthorized unmount in util-linux’s libmount
CVE-2021-3998Unexpected return value from glibc’s realpath()
CVE-2021-3999Off-by-one buffer overflow/underflow in glibc’s getcwd()
CVE-2021-3997Uncontrolled recursion in systemd’s systemd-tmpfiles

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, CVE-2021-44731)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/128150/hacking/cve-2021-44731-linux-privilege-escalation.html