[Git][security-tracker-team/security-tracker][master] lts: snapd not-affected in bookworm/bullseye

Utkarsh Gupta (@utkarsh) utkarsh at debian.org
Sun Jul 26 15:22:20 BST 2026



Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker


Commits:
086b35e9 by Utkarsh Gupta at 2026-07-26T19:49:05+05:30
lts: snapd not-affected in bookworm/bullseye

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -6213,6 +6213,8 @@ CVE-2016-20096 (Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an u
 CVE-2026-8933 (A local privilege escalation vulnerability exists in snap-confine, a s ...)
 	- snapd <unfixed> (bug #1142551)
 	[trixie] - snapd <ignored> (Not exploitable as snap-confine not yet installed with set capabilities)
+	[bookworm] - snapd <not-affected> (Only set-capabilities snap-confine is vulnerable; Debian installs it setuid-root and sc_replicate_base_rootfs() is not present)
+	[bullseye] - snapd <not-affected> (Only set-capabilities snap-confine is vulnerable; Debian installs it setuid-root and sc_replicate_base_rootfs() is not present)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/21/1
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/21/2
 	NOTE: Non-suid snap-confine only introduced in debian/2.71-1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/086b35e9eb5e73e9ae9fe879dfee363fb7cc8fa3

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/086b35e9eb5e73e9ae9fe879dfee363fb7cc8fa3
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260726/f42733a8/attachment.htm>


More information about the debian-security-tracker-commits mailing list