CVE-2019-7304: Local privilege escalation via snapd socket
Published Apr 23, 2019
·Updated
Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root. This issue affects: Canonical snapd versions prior to 2.37.1.
Affected Software
6 affected componentsFixes available
Canonical snapd<2.37.1
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
debian/snapd
2.49-1+deb11u22.57.6-12.68.3-32.71-32.72-1
Event History
Apr 23, 2019
CVE Published
via MITRE·03:57 PM
Data Sourced
via MITRE·03:57 PM
DescriptionSeverityWeakness
Aug 4, 2024
Data Sourced
via Launchpad·08:54 PM
Description
Feb 23, 2026
Data Sourced
via Ubuntu·05:00 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·05:00 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-7304.
2
What is the severity level of CVE-2019-7304?
The severity level of CVE-2019-7304 is critical with a severity value of 9.8.
3
Which versions of Canonical snapd are affected by CVE-2019-7304?
Versions of Canonical snapd prior to 2.37.1 are affected by CVE-2019-7304.
4
Is Ubuntu Linux affected by CVE-2019-7304?
Yes, Ubuntu Linux versions 14.04, 16.04, 18.04, and 18.10 are affected by CVE-2019-7304.
5
How can I fix the CVE-2019-7304 vulnerability?
To fix the CVE-2019-7304 vulnerability, update Canonical snapd to version 2.37.1 or later.