CVE-2026-3888

Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:22.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:24.04:*:*:*:lts:*:*:*

History

04 Jun 2026, 14:43

Type Values Removed Values Added
References () https://blog.qualys.com/vulnerabilities-threat-research/2026/03/17/cve-2026-3888-important-snap-flaw-enables-local-privilege-escalation-to-root - () https://blog.qualys.com/vulnerabilities-threat-research/2026/03/17/cve-2026-3888-important-snap-flaw-enables-local-privilege-escalation-to-root - Mitigation, Third Party Advisory
References () https://cdn2.qualys.com/advisory/2026/03/17/snap-confine-systemd-tmpfiles.txt - () https://cdn2.qualys.com/advisory/2026/03/17/snap-confine-systemd-tmpfiles.txt - Third Party Advisory
References () https://discourse.ubuntu.com/t/snapd-local-privilege-escalation-cve-2026-3888 - () https://discourse.ubuntu.com/t/snapd-local-privilege-escalation-cve-2026-3888 - Mitigation, Third Party Advisory
References () https://ubuntu.com/security/CVE-2026-3888 - () https://ubuntu.com/security/CVE-2026-3888 - Third Party Advisory
References () https://ubuntu.com/security/notices/USN-8102-1 - () https://ubuntu.com/security/notices/USN-8102-1 - Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2026/03/18/1 - () http://www.openwall.com/lists/oss-security/2026/03/18/1 - Mailing List, Third Party Advisory
Summary
  • (es) La escalada de privilegios local en snapd en Linux permite a los atacantes locales obtener privilegios de root al recrear el directorio /tmp privado de snap cuando systemd-tmpfiles está configurado para limpiar automáticamente este directorio. Este problema afecta a Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS y 24.04 LTS.
First Time Canonical ubuntu Linux
Canonical
CPE cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:22.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:24.04:*:*:*:lts:*:*:*

18 Mar 2026, 04:17

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/03/18/1 -

18 Mar 2026, 00:16

Type Values Removed Values Added
References
  • () https://blog.qualys.com/vulnerabilities-threat-research/2026/03/17/cve-2026-3888-important-snap-flaw-enables-local-privilege-escalation-to-root -
  • () https://cdn2.qualys.com/advisory/2026/03/17/snap-confine-systemd-tmpfiles.txt -
  • () https://discourse.ubuntu.com/t/snapd-local-privilege-escalation-cve-2026-3888 -
  • () https://ubuntu.com/security/notices/USN-8102-1 -

17 Mar 2026, 14:20

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-17 14:16

Updated : 2026-06-04 14:43


NVD link : CVE-2026-3888

Mitre link : CVE-2026-3888

CVE.ORG link : CVE-2026-3888


JSON object : View

Products Affected

canonical

  • ubuntu_linux
CWE
CWE-268

Privilege Chaining