CVE-2021-44730: snapd could be made to escalate privileges and run programs as administrator
Last updated 25 August 2025
Other sources
snapd 2.54.2 did not properly validate the location of the snap-confine binary. A local attacker who can hardlink this binary to another location to cause snap-confine to execute other arbitrary binaries and hence gain privilege escalation. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-44730?
CVE-2021-44730 is a vulnerability in snapd 2.54.2 that allows a local attacker to execute arbitrary binaries with escalated privileges by hardlinking the snap-confine binary to another location.
What is the severity of CVE-2021-44730?
CVE-2021-44730 has a severity score of 8.8, which is considered high.
How can I fix CVE-2021-44730?
To fix CVE-2021-44730, update snapd to version 2.54.3+18.04, 2.54.3+20.04, or 2.54.3+21.10.1, depending on your system version.
What software versions are affected by CVE-2021-44730?
Versions of snapd up to and including 2.54.2 are affected by CVE-2021-44730.
Where can I find more information about CVE-2021-44730?
More information about CVE-2021-44730 can be found at the following references: [Reference 1](http://www.openwall.com/lists/oss-security/2022/02/18/2), [Reference 2](http://www.openwall.com/lists/oss-security/2022/02/23/1), [Reference 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3QTBN7LLZISXIA4KU4UKDR27Q5PXDS2U/).