CVE-2023-1523: Critical severity snapcraft snapd vulnerability
Last updated 24 July 2024
Other sources
Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause arbitrary commands to be executed outside of the snap sandbox after the snap exits. Graphical terminal emulators like xterm, gnome-terminal and others are not affected - this can only be exploited when snaps are run on a virtual console.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-1523?
The severity of CVE-2023-1523 is critical with a severity value of 10.
Which software is affected by CVE-2023-1523?
The affected software is snapd, specifically versions 2.58+18.04.1, 2.58+20.04.1, 2.58+22.04.1, 2.58+22.10.1, 2.59.1+23.04ubuntu1.1, 2.59.5-1, and 2.54.3+16.04.0ubuntu0.1~.
How can a malicious snap exploit CVE-2023-1523?
By using the TIOCLINUX ioctl request, a malicious snap can inject arbitrary contents into the input of the controlling terminal, allowing it to execute arbitrary commands outside of the snap sandbox after the snap exits.
What are the affected versions of Ubuntu for CVE-2023-1523?
The affected versions of Ubuntu are 16.04, 18.04, 20.04, 22.04, and 22.10.
How can I fix CVE-2023-1523?
To fix CVE-2023-1523, update snapd to version 2.58+18.04.1, 2.58+20.04.1, 2.58+22.04.1, 2.58+22.10.1, 2.59.1+23.04ubuntu1.1, 2.59.5-1, or 2.54.3+16.04.0ubuntu0.1~ depending on your system's version.