CVE-2024-1724: snapd allows $HOME/bin symlink
In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict writes to the $HOME/bin path. In Ubuntu, when this path exists, it is automatically added to the users PATH. An attacker who could convince a user to install a malicious snap which used the 'home' plug could use this vulnerability to install arbitrary scripts into the users PATH which may then be run by the user outside of the expected snap sandbox and hence allow them to escape confinement.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1724?
CVE-2024-1724 has been classified as a medium severity vulnerability due to improper restrictions on the $HOME/bin path.
How do I fix CVE-2024-1724?
To fix CVE-2024-1724, upgrade snapd to version 2.62 or later.
Which versions of snapd are affected by CVE-2024-1724?
CVE-2024-1724 affects snapd versions prior to 2.62.
What impact does CVE-2024-1724 have on system security?
CVE-2024-1724 can allow an attacker to manipulate scripts in the $HOME/bin directory, potentially leading to privilege escalation.
Is there a patch available for CVE-2024-1724?
Yes, a patch is available in snapd versions 2.62 and higher.