CVE-2021-4120: snapd could be made to bypass intended access restrictions through snap content interfaces and layout paths
Last updated 25 August 2025
Other sources
snapd 2.54.2 fails to perform sufficient validation of snap content interface and layout paths, resulting in the ability for snaps to inject arbitrary AppArmor policy rules via malformed content interface and layout declarations and hence escape strict snap confinement. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-4120?
CVE-2021-4120 is a vulnerability in snapd 2.54.2 that allows snaps to inject arbitrary AppArmor policy rules and escape strict snap confinement.
How severe is CVE-2021-4120?
CVE-2021-4120 has a severity rating of 7.8 (high).
Which versions of snapd are affected?
Version 2.54.2 of snapd is affected.
How can I fix CVE-2021-4120?
To fix CVE-2021-4120, update snapd to version 2.54.3 or higher.
Where can I find more information about CVE-2021-4120?
You can find more information about CVE-2021-4120 at the following references: [Link 1](http://www.openwall.com/lists/oss-security/2022/02/18/2), [Link 2](https://bugs.launchpad.net/snapd/+bug/1949368), [Link 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3QTBN7LLZISXIA4KU4UKDR27Q5PXDS2U/).