Summary: | <app-containers/snapd-2.54.3: Multiple vulnerabilities | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Sam James <sam> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | trivial | CC: | zmedico |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | ~1 [noglsa] | ||
Package list: | Runtime testing required: | --- |
Description
Sam James
![]() ![]() ![]() ![]() CVE-2021-3155 ( snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local attacker to read information that should have been private. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1 https://github.com/snapcore/snapd/commit/6bcaeeccd16ed8298a301dd92f6907f88c24cc85 https://github.com/snapcore/snapd/commit/7d2a966620002149891446a53cf114804808dcca CVE-2021-4120: snapd 2.54.2 fails to perform sufficient validation of snap content interface and layout paths, resulting in the ability for snaps to inject arbitrary AppArmor policy rules via malformed content interface and layout declarations and hence escape strict snap confinement. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1 The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=46f127f94639382842e87b71f8edaadfe2ef0fd2 commit 46f127f94639382842e87b71f8edaadfe2ef0fd2 Author: Zac Medico <zmedico@gentoo.org> AuthorDate: 2022-02-18 18:19:14 +0000 Commit: Zac Medico <zmedico@gentoo.org> CommitDate: 2022-02-18 18:20:33 +0000 app-containers/snapd: Remove vulnerable version Bug: https://bugs.gentoo.org/833584 Package-Manager: Portage-3.0.30, Repoman-3.0.3 Signed-off-by: Zac Medico <zmedico@gentoo.org> app-containers/snapd/Manifest | 3 - app-containers/snapd/snapd-2.53.4.ebuild | 180 ------------------------------- app-containers/snapd/snapd-2.54.1.ebuild | 180 ------------------------------- app-containers/snapd/snapd-2.54.2.ebuild | 180 ------------------------------- 4 files changed, 543 deletions(-) https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=b954000843bde5a248db161bbfd178ef58f1f06b commit b954000843bde5a248db161bbfd178ef58f1f06b Author: Zac Medico <zmedico@gentoo.org> AuthorDate: 2022-02-18 18:17:14 +0000 Commit: Zac Medico <zmedico@gentoo.org> CommitDate: 2022-02-18 18:20:32 +0000 app-containers/snapd: Bump to version 2.54.3 Bug: https://bugs.gentoo.org/833584 Package-Manager: Portage-3.0.30, Repoman-3.0.3 Signed-off-by: Zac Medico <zmedico@gentoo.org> app-containers/snapd/Manifest | 1 + app-containers/snapd/snapd-2.54.3.ebuild | 180 +++++++++++++++++++++++++++++++ 2 files changed, 181 insertions(+) Thanks Zac! |