<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T19:45:26.180827+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-8933</id>
    <title>CVE-2026-8933 — snap-confine Local Privilege Escalation via Capabilities Misconfiguration or Flaw in Execution Environment Setup</title>
    <updated>2026-10-10T19:45:26.184573+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> snapd, Canonical Ubuntu 26.04 LTS, Canonical Ubuntu 24.04 LTS, Canonical Ubuntu 22.04 LTS</p>
<p>A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations).
Due to a flaw in how privilege boundaries or security sandboxes are initialized when the binary runs under limited ambient capabilities, a local, unprivileged attacker can exploit this behavior to bypass intended restrictions and execute arbitrary code. Successful exploitation allows the local user to elevate their privileges to full root authority.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-8933"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/usn-8579-1</id>
    <title>USN-8579-1 — snapd vulnerabilities</title>
    <updated>2026-10-10T19:45:26.184634+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: snapd, Ubuntu:Pro:18.04:LTS: snapd, Ubuntu:Pro:20.04:LTS: snapd, Ubuntu:22.04:LTS: snapd, Ubuntu:24.04:LTS: snapd, Ubuntu:26.04:LTS: snapd</p>
<p>James Henstridge discovered that snapd's default apparmor template did
not restrict access to systemd-userdbd varlink interface. A local
attacker could possibly use this issue to obtain sensitive information.
(CVE-2024-5300)</p>
<p>Qualys discovered that snap-confine can be tricked to create
attacker-controlled files at certain privileged locations. A local
attacker could possibly use this issue to bypass intended restrictions
and escalate privileges to root. This issue only affected
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-8933)</p>
<p>Zygmunt Krynicki discovered that snapd's default seccomp template
did not restrict the creation of executables with the set-user-ID
attribute. A local attacker could possibly use this issue to create
and execute setuid binaries. (CVE-2026-15226)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/usn-8579-1"/>
  </entry>
</feed>
