CVE-2021-3155: snapd created ~/snap with too-wide permissions
Last updated 25 August 2025
Other sources
snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local attacker to read information that should have been private. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-3155?
CVE-2021-3155 is a vulnerability in snapd 2.54.2 and earlier that allowed a local attacker to read information that should have been private.
How severe is CVE-2021-3155?
CVE-2021-3155 has a severity score of 5.5, which is considered medium.
Which versions of snapd are affected by CVE-2021-3155?
snapd versions 2.54.2 and earlier are affected by CVE-2021-3155.
How can I fix CVE-2021-3155?
To fix CVE-2021-3155, update snapd to versions 2.54.3+18.04, 2.54.3+20.04, or 2.54.3+21.10.1.
Where can I find more information about CVE-2021-3155?
You can find more information about CVE-2021-3155 in the following references: [Link 1](https://github.com/snapcore/snapd/commit/6bcaeeccd16ed8298a301dd92f6907f88c24cc85), [Link 2](https://github.com/snapcore/snapd/commit/7d2a966620002149891446a53cf114804808dcca), [Link 3](https://ubuntu.com/security/notices/USN-5292-1).