Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
5391a71d by Salvatore Bonaccorso at 2026-08-21T16:44:25+02:00
Update status for snapd issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -36799,21 +36799,25 @@ CVE-2025-66390 (In Microsoft Azure API Management 
through 2025-10-17, when self-
 CVE-2016-20096 (Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an 
unauthe ...)
        NOT-FOR-US: Linknat
 CVE-2026-8933 (A local privilege escalation vulnerability exists in 
snap-confine, a s ...)
-       - snapd <unfixed> (bug #1142551)
+       - snapd 2.76.3-1 (bug #1142551)
        [trixie] - snapd <ignored> (Not exploitable as snap-confine not yet 
installed with set capabilities)
        [bookworm] - snapd <not-affected> (Only set-capabilities snap-confine 
is vulnerable; Debian installs it setuid-root and sc_replicate_base_rootfs() is 
not present)
        [bullseye] - snapd <not-affected> (Only set-capabilities snap-confine 
is vulnerable; Debian installs it setuid-root and sc_replicate_base_rootfs() is 
not present)
        NOTE: https://www.openwall.com/lists/oss-security/2026/07/21/1
        NOTE: https://www.openwall.com/lists/oss-security/2026/07/21/2
+       NOTE: Fixed by: 
https://github.com/canonical/snapd/commit/cec05b3f0915e3ae5936e923214ce1cb0fb52b3d
 (2.76.1)
+       NOTE: Fixed by: 
https://github.com/canonical/snapd/commit/cc94fdb321d558362e806d8593b89a29737ac52c
 (2.76.1)
        NOTE: Non-suid snap-confine only introduced in debian/2.71-1
 CVE-2024-5300 (An access control bypass and information disclosure 
vulnerability exis ...)
-       - snapd <unfixed> (bug #1142551)
+       - snapd 2.76.3-1 (bug #1142551)
        [trixie] - snapd <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2026/07/21/1
+       NOTE: Fixed by: 
https://github.com/canonical/snapd/commit/689bf91556ff93b13b39ed4cf951d646e4b306a2
 (2.76.1)
 CVE-2026-15226 (A sandbox confinement bypass vulnerability exists in Canonical 
snapd w ...)
-       - snapd <unfixed> (bug #1142551)
+       - snapd 2.76.3-1 (bug #1142551)
        [trixie] - snapd <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2026/07/21/1
+       NOTE: Fixed by: 
https://github.com/canonical/snapd/commit/f32fe221c5bcccac3a328efb89fe06286405385e
 (2.76.1)
 CVE-2026-16361 (Memory safety bugs present in Thunderbird ESR 140.12. Some of 
these bu ...)
        {DSA-6418-1 DSA-6394-1 DLA-4727-1 DLA-4695-1}
        - firefox-esr 140.13.0esr-1



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5391a71d9856971892415c03a7d6bf6e8c15d82a

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5391a71d9856971892415c03a7d6bf6e8c15d82a
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to