CVE-2020-27352
Last modified
CVE-2020-27352 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd will move processes from the containers created and managed by these snaps into the cgroup of the main daemon within the snap itself when reloading system units. This may grant additional privileges to a container within the snap that were not originally intended.. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd will move processes from the containers created and managed by these snaps into the cgroup of the main daemon within the snap itself when reloading system units. This may grant additional privileges to a container within the snap that were not originally intended.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Snapd | < 2.48.3 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 18.04 |
| Canonical | Ubuntu Linux | 20.04 |
| Canonical | Ubuntu Linux | 20.10 |
References
- https://bugs.launchpad.net/snapd/+bug/1910456Exploit, Issue Tracking
- https://ubuntu.com/security/notices/USN-4728-1Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-27352Third Party Advisory
- https://bugs.launchpad.net/snapd/+bug/1910456Exploit, Issue Tracking
- https://ubuntu.com/security/notices/USN-4728-1Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-27352Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2020-27352?
How severe is CVE-2020-27352?
How do I fix CVE-2020-27352?
Are you affected by CVE-2020-27352?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
