Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34275
HistoryFeb 18, 2022 - 7:02 a.m.

Privilege Escalation

2022-02-1807:02:52
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
28
privilege escalation
github
snapd

EPSS

0

Percentile

5.1%

github.com/snapcore/snapd is vulnerable to privilege escalation. The sc_open_snapd_tool function of tool.c does not properly validate the location of the snap-confine binary, allowing an attacker to hardlink setuid binaries to another location when fs.protected_hardlinks is 0.