Exploitation Summary
EIP tracks 7 public exploits for CVE-2026-3888. PoCs published by hewhomusntbenamed, DanielTangnes, nomaisthere.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-3888, a local privilege escalation (LPE) vulnerability in snap-confine and systemd-tmpfiles. The exploit leverages a race condition to swap directories and inject a malicious payload, achieving root access.
Description
Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.
Exploits (7)
This repository contains a functional exploit for CVE-2026-3888, a local privilege escalation (LPE) vulnerability in snap-confine and systemd-tmpfiles. The exploit leverages a race condition to swap directories and inject a malicious payload, achieving root access.
This repository contains a functional privilege escalation exploit for CVE-2026-3888, targeting a race condition in snap-confine to achieve root access. The exploit involves namespace manipulation and dynamic linker hijacking via a crafted library.
This repository provides a detailed technical analysis of CVE-2026-3888, a local privilege escalation vulnerability in Ubuntu 24.04 involving the interaction between snap-confine and systemd-tmpfiles. It includes in-depth explanations of the race condition, exploitation steps, and mitigations.
This repository contains a functional local privilege escalation (LPE) exploit for CVE-2026-3888, targeting a TOCTOU race condition between `snap-confine` and `systemd-tmpfiles` on Ubuntu 24.04+. Two variants are provided: SUID and Capabilities, both leveraging race conditions to overwrite critical files and escalate privileges to root.
This PoC exploits a race condition in the Snap package manager (hello-world snap) to achieve local privilege escalation by symlinking a malicious shared library into a target directory. The payload executes arbitrary commands with elevated privileges upon successful exploitation.
This repository contains a bash script designed to detect and remediate CVE-2026-3888 on Ubuntu systems by checking the installed version of snapd and applying patches if necessary. It does not exploit the vulnerability but instead automates the patching process.
This repository contains a functional PoC for CVE-2026-3888, a local privilege escalation vulnerability in snapd. The exploit leverages a race condition between snap-confine and systemd-tmpfiles to recreate the /tmp/.snap directory with malicious files, leading to root privilege execution.
References (6)
Scores
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H