CVE-2022-3328: Race Condition
Published Jan 8, 2024
·Updated
Last updated 24 July 2024
Other sources
Race condition in snap-confine's mustmkdirandopenwithperms()
— GitHub
Race condition in snap-confine's mustmkdirandopenwithperms()
— Launchpad
Affected Software
8 affected componentsFixes available
go/github.com/snapcore/snapd<2.57.6
2.57.6
Canonical snapd<2.61.1
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=20.04
Canonical Ubuntu Linux=22.04
Canonical Ubuntu Linux=22.10
debian/snapd
2.49-1+deb11u22.57.6-12.68.3-2
Event History
Jan 8, 2024
CVE Published
via MITRE·06:04 PM
Data Sourced
via MITRE·06:04 PM
DescriptionSeverity
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·06:30 PM
Jan 12, 2024
Data Sourced
via Launchpad·06:13 PM
Description
Jun 23, 2025
Data Sourced
via Ubuntu·02:50 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·02:51 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-3328?
CVE-2022-3328 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2022-3328?
To fix CVE-2022-3328, update your 'snapd' package to version 2.57.5+18.04ubuntu0.1, 2.57.5+20.04ubuntu0.1, 2.57.5+22.04ubuntu0.1, or later.
3
Which versions of 'snapd' are affected by CVE-2022-3328?
CVE-2022-3328 affects 'snapd' versions prior to 2.57.5+18.04ubuntu0.1, 2.57.5+20.04ubuntu0.1, 2.57.5+22.04ubuntu0.1, and others.
4
What system is primarily affected by CVE-2022-3328?
CVE-2022-3328 primarily affects Ubuntu operating systems utilizing the 'snapd' package.
5
Is there an alternative solution for CVE-2022-3328 apart from updating?
The recommended approach for CVE-2022-3328 is to apply the necessary updates, as alternative solutions may not fully mitigate the vulnerability.