Canonical patches three snapd flaws including two high-severity escalations
Local attackers could gain root privileges or break snap confinement on multiple Ubuntu LTS releases.
Canonical has shipped fixes for three vulnerabilities in snapd, two of them rated high severity, that let local attackers escalate privileges or escape confinement on default Ubuntu installations.
CVE-2026-8933, found by Qualys and scored 7.8, allows local privilege escalation. It affects default installs of Ubuntu 22.04 LTS, 24.04 LTS, and 26.04 LTS. CVE-2026-15226, discovered by Canonical’s Zygmunt Krynicki and scored 8.4, lets an attacker move from confined root to unconfined root. CVE-2024-5300, found by Canonical’s James Henstridge and scored 5.6, lets a sandboxed application read hashed user passwords on releases from 16.04 LTS through 26.04 LTS where systemd-userdbd is present.
Security updates for the snapd package are already in the Ubuntu archives for the affected releases. Updates to the snapd and core snaps are pending publication on the stable channel; the FIPS channel will not receive them. Users should ensure both the archive package and the snaps are current, either by waiting for automatic refresh or forcing an update.