[Git][security-tracker-team/security-tracker][master] Update status for snapd issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 21 15:44:43 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5391a71d by Salvatore Bonaccorso at 2026-08-21T16:44:25+02:00
Update status for snapd issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -36799,21 +36799,25 @@ CVE-2025-66390 (In Microsoft Azure API Management through 2025-10-17, when self-
 CVE-2016-20096 (Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthe ...)
 	NOT-FOR-US: Linknat
 CVE-2026-8933 (A local privilege escalation vulnerability exists in snap-confine, a s ...)
-	- snapd <unfixed> (bug #1142551)
+	- snapd 2.76.3-1 (bug #1142551)
 	[trixie] - snapd <ignored> (Not exploitable as snap-confine not yet installed with set capabilities)
 	[bookworm] - snapd <not-affected> (Only set-capabilities snap-confine is vulnerable; Debian installs it setuid-root and sc_replicate_base_rootfs() is not present)
 	[bullseye] - snapd <not-affected> (Only set-capabilities snap-confine is vulnerable; Debian installs it setuid-root and sc_replicate_base_rootfs() is not present)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/21/1
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/21/2
+	NOTE: Fixed by: https://github.com/canonical/snapd/commit/cec05b3f0915e3ae5936e923214ce1cb0fb52b3d (2.76.1)
+	NOTE: Fixed by: https://github.com/canonical/snapd/commit/cc94fdb321d558362e806d8593b89a29737ac52c (2.76.1)
 	NOTE: Non-suid snap-confine only introduced in debian/2.71-1
 CVE-2024-5300 (An access control bypass and information disclosure vulnerability exis ...)
-	- snapd <unfixed> (bug #1142551)
+	- snapd 2.76.3-1 (bug #1142551)
 	[trixie] - snapd <no-dsa> (Minor issue)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/21/1
+	NOTE: Fixed by: https://github.com/canonical/snapd/commit/689bf91556ff93b13b39ed4cf951d646e4b306a2 (2.76.1)
 CVE-2026-15226 (A sandbox confinement bypass vulnerability exists in Canonical snapd w ...)
-	- snapd <unfixed> (bug #1142551)
+	- snapd 2.76.3-1 (bug #1142551)
 	[trixie] - snapd <no-dsa> (Minor issue)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/21/1
+	NOTE: Fixed by: https://github.com/canonical/snapd/commit/f32fe221c5bcccac3a328efb89fe06286405385e (2.76.1)
 CVE-2026-16361 (Memory safety bugs present in Thunderbird ESR 140.12. Some of these bu ...)
 	{DSA-6418-1 DSA-6394-1 DLA-4727-1 DLA-4695-1}
 	- firefox-esr 140.13.0esr-1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5391a71d9856971892415c03a7d6bf6e8c15d82a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5391a71d9856971892415c03a7d6bf6e8c15d82a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260821/263422f5/attachment.htm>


More information about the debian-security-tracker-commits mailing list