CRITICAL
Race condition in snap-confine's must_mkdir_and_open_with_perms()
Published Jan 8, 2024
9.0
CRITICALCVSS 4.0
EPSS 0.38%
Description
Race condition in snap-confine's must_mkdir_and_open_with_perms()
Affected products
-
- Version 0StatusaffectedConstraints<2.61.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Canonical Ltd. | Snapd | n/a |
|
OR
- < 2.61.1
- 16.04
- 18.04
- 20.04
- 22.04
- 22.10
No data.
No Red Hat product state for this CVE.
github.com/snapcore/snapd
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/snapcore/snapd | 0 | not fixed |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3328 issue-trackingThird Party Advisory
- https://github.com/advisories/GHSA-cjqf-877p-7m3f Advisory
- https://github.com/snapcore/snapd/commit/21ebc51f00b8a1417888faa2e83a372fd29d0f5e
- https://github.com/snapcore/snapd/commit/6226cdc57052f4b7057d92f2e549aa169e35cd2d
- https://github.com/snapcore/snapd/pull/12380
- https://nvd.nist.gov/vuln/detail/CVE-2022-3328
- https://ubuntu.com/security/notices/USN-5753-1 third-party-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3328 | issue-trackingThird Party Advisory | |
| https://github.com/advisories/GHSA-cjqf-877p-7m3f | Advisory | |
| https://github.com/snapcore/snapd/commit/21ebc51f00b8a1417888faa2e83a372fd29d0f5e | ||
| https://github.com/snapcore/snapd/commit/6226cdc57052f4b7057d92f2e549aa169e35cd2d | ||
| https://github.com/snapcore/snapd/pull/12380 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2022-3328 | ||
| https://ubuntu.com/security/notices/USN-5753-1 | third-party-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner canonical
Published Jan 8, 2024
Updated Jun 3, 2025
Reserved Sep 27, 2022
Link CVE-2022-3328
CISA Vulnrichment
GHSA-CJQF-877P-7M3F Updated May 8, 2025