Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
5391a71d by Salvatore Bonaccorso at 2026-08-21T16:44:25+02:00
Update status for snapd issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -36799,21 +36799,25 @@ CVE-2025-66390 (In Microsoft Azure API Management
through 2025-10-17, when self-
CVE-2016-20096 (Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an
unauthe ...)
NOT-FOR-US: Linknat
CVE-2026-8933 (A local privilege escalation vulnerability exists in
snap-confine, a s ...)
- - snapd <unfixed> (bug #1142551)
+ - snapd 2.76.3-1 (bug #1142551)
[trixie] - snapd <ignored> (Not exploitable as snap-confine not yet
installed with set capabilities)
[bookworm] - snapd <not-affected> (Only set-capabilities snap-confine
is vulnerable; Debian installs it setuid-root and sc_replicate_base_rootfs() is
not present)
[bullseye] - snapd <not-affected> (Only set-capabilities snap-confine
is vulnerable; Debian installs it setuid-root and sc_replicate_base_rootfs() is
not present)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/21/1
NOTE: https://www.openwall.com/lists/oss-security/2026/07/21/2
+ NOTE: Fixed by:
https://github.com/canonical/snapd/commit/cec05b3f0915e3ae5936e923214ce1cb0fb52b3d
(2.76.1)
+ NOTE: Fixed by:
https://github.com/canonical/snapd/commit/cc94fdb321d558362e806d8593b89a29737ac52c
(2.76.1)
NOTE: Non-suid snap-confine only introduced in debian/2.71-1
CVE-2024-5300 (An access control bypass and information disclosure
vulnerability exis ...)
- - snapd <unfixed> (bug #1142551)
+ - snapd 2.76.3-1 (bug #1142551)
[trixie] - snapd <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/21/1
+ NOTE: Fixed by:
https://github.com/canonical/snapd/commit/689bf91556ff93b13b39ed4cf951d646e4b306a2
(2.76.1)
CVE-2026-15226 (A sandbox confinement bypass vulnerability exists in Canonical
snapd w ...)
- - snapd <unfixed> (bug #1142551)
+ - snapd 2.76.3-1 (bug #1142551)
[trixie] - snapd <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/21/1
+ NOTE: Fixed by:
https://github.com/canonical/snapd/commit/f32fe221c5bcccac3a328efb89fe06286405385e
(2.76.1)
CVE-2026-16361 (Memory safety bugs present in Thunderbird ESR 140.12. Some of
these bu ...)
{DSA-6418-1 DSA-6394-1 DLA-4727-1 DLA-4695-1}
- firefox-esr 140.13.0esr-1
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5391a71d9856971892415c03a7d6bf6e8c15d82a
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5391a71d9856971892415c03a7d6bf6e8c15d82a
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits