ON
← Back to feed
Right extension loophole in Ubuntu by snap
Germany💻 Technology9 hr. ago

Right extension loophole in Ubuntu by snap

A security vulnerability has been discovered in the 'snap-confine' package used by Ubuntu, allowing local users to escalate their privileges to root level. The issue arises from a non-standard configuration using 'set-capabilities' instead of the intended 'set-uid-root' method, which leaves temporary directories created under '/tmp' vulnerable during initialization. This allows attackers to bypass sandboxing restrictions and execute arbitrary code. Security firm Qualys reported the flaw, referencing the official Ubuntu advisory and the NIST vulnerability database. Updated packages have been released to address the issue, and users are advised to apply them promptly.

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and your personalized For You feed.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and your personalized For You feed.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and your personalized For You feed.

Become a Supporter

Go to the primary sources (3)

The official sources this coverage is built on. Read them directly to bypass framing.

1 reports

heise online logoheise onlineIndependentCenter9 hr. ago
Right extension loophole in Ubuntu by snap

A security vulnerability has been discovered in the 'snap-confine' package used by Ubuntu, allowing local users to escalate their privileges to root level. The issue arises from a non-standard configuration using 'set-capabilities' instead of the intended 'set-uid-root' method, which leaves temporary directories created under '/tmp' vulnerable during initialization. This allows attackers to bypass sandboxing restrictions and execute arbitrary code. Security firm Qualys reported the flaw, referencing the official Ubuntu advisory and the NIST vulnerability database. Updated packages have been released to address the issue, and users are advised to apply them promptly.

Bias read (Center): The article discusses a technical vulnerability in software and provides factual information about the security flaw, its cause, and the recommended fix. There is no political framing, bias, or ideological emphasis present in the content.

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €5/month.

Become a Supporter

Related stories