Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5005 articles · 188941 vulns · 37/41 feeds (7d)
← Back to list
5.6
CVE-2024-5300PATCHED
Canonical · snapd

AppArmor Base Profile Misconfiguration in snapd Permits Confined Snaps Unauthorized Access to Hashed Passwords via systemd-userdbd

Description

An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules located in /etc/apparmor.d/abstractions/nss-systemd (inherited via ) inadvertently permit strictly confined snap applications, which lack the privileged account-control interface, to interact directly with the io.systemd.Multiplexer and io.systemd.NameServiceSwitch UNIX domain sockets under /run/systemd/userdb/. On systems where the systemd-userdbd service is installed and operational, the service fails to distinguish between an unconfined root user on the host system and a restricted root user running within a snap application's sandbox (such as a daemon or configuration hook). Because systemd-userdbd returns "complete" user records—including sensitive hashed user passwords from /etc/shadow—when queried by a process running as root, a compromised or malicious strictly confined snap executing code as root can successfully query the Varlink interface to retrieve all system password hashes, bypassing intended snap sandbox restrictions. This issue is mitigated by the fact that systemd-userdbd is not installed by default on standard Ubuntu deployments.

Affected Products

VendorProductVersions
Canonicalsnapd0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
canonicalsnapcert_advisory90%
canonicallinuxcert_advisory90%

References

  • https://ubuntu.com/security/CVE-2024-5300(vdb-entry, issue-tracking)

Related News (2 articles)

Tier B
BSI Advisories21d ago
[NEU] [hoch] snapd: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB22d ago
CVE-2024-5300 | Canonical snapd 16.04 LTS up to 24.04 LTS AppArmor nss-systemd access control
→ No new info (linked only)
CVSS 3.15.6 MEDIUM
VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
2.76.12.76+ubuntu26.04.32.76+ubuntu24.04.12.76+ubuntu22.04.12.67.1+20.04ubuntu1~esm22.61.4ubuntu0.18.04.1+esm32.61.4ubuntu0.16.04.1+esm3
CWECWE-212
PublishedJul 21, 2026
Last enriched22d agov2
Trending Score3
Source articles2
Independent2
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-45893EXP
apparmor: Fix & Optimize table creation from possibly unaligned memory
Trending: 9
HIGHCVE-2026-8933
snap-confine Local Privilege Escalation via Capabilities Misconfiguration or Flaw in Execution Environment Setup
Trending: 8
HIGHCVE-2026-15226
snapd snap-confine Sandbox Confinement Bypass via Omission of setuid Restriction in Seccomp Templates
Trending: 4
CRITICALCVE-2026-11386
ubuntu-pro-client Input Validation Vulnerability Leading to Arbitrary APT Directive Injection and Remote Code Execution
Trending: 3
MEDIUMCVE-2026-9494
ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure in Process Command Line
Trending: 2

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 21, 2026
Discovered by ZDM
Jul 21, 2026
Updated: vendor, product, affectedVersions
Jul 21, 2026
Patch Available
Jul 22, 2026

Version History

v2
Last enriched 22d ago
v2Tier C22d ago

Added vendor (Canonical) and product (snapd) information, and expanded affected versions to include specific Ubuntu LTS releases (16.04 LTS through 24.04 LTS) instead of generic version '0'

vendorproductaffectedVersions
via VulDB
v122d ago

Initial creation