CVE-2019-7303: Snapd seccomp filter TIOCSTI ioctl bypass
A vulnerability in the seccomp filters of Canonical snapd before version 2.37.4 allows a strict mode snap to insert characters into a terminal on a 64-bit host. The seccomp rules were generated to match 64-bit ioctl(2) commands on a 64-bit platform; however, the Linux kernel only uses the lower 32 bits to determine which ioctl(2) commands to run. This issue affects: Canonical snapd versions prior to 2.37.4.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-7303?
CVE-2019-7303 is a vulnerability in the seccomp filters of Canonical snapd before version 2.37.4.
What is the severity of CVE-2019-7303?
CVE-2019-7303 has a severity rating of 7.5 (high).
Which software versions are affected by CVE-2019-7303?
Canonical snapd before version 2.37.4, and Canonical Ubuntu Linux versions 14.04, 16.04, 18.04, and 18.10 are affected by CVE-2019-7303.
How can I fix the CVE-2019-7303 vulnerability?
To fix CVE-2019-7303, update to Canonical snapd version 2.37.4 or higher.
Where can I find more information about CVE-2019-7303?
You can find more information about CVE-2019-7303 on the Ubuntu Security Notice page (https://usn.ubuntu.com/3917-1/).