CVE-2024-5138

HIGH

snapd 2.51.6-2.63.1 - Privilege Escalation via snapctl Command-Line Argument Parsing

Title source: llm
STIX 2.1

Description

The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. It was found that snapctl did not properly parse command-line arguments, allowing an unprivileged user to trigger an authorised action on behalf of the snap that would normally require administrator privileges to perform. This could possibly allow an unprivileged user to perform a denial of service or similar.

Scores

CVSS v3 8.1
EPSS 0.0061
EPSS Percentile 70.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (2)
canonical/snapd 2.51.6 - 2.63.1
snapcore/snapd 2.51.6 - 2.63.1Go
Published May 31, 2024
Tracked Since Feb 18, 2026