CVE-2026-3888
7.8 HIGHLocal privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory wh...
Published: 2026-03-17 · Last updated: 2026-06-04
Severity and scoring
- CVSS
- 7.8 HIGH
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
- CWE
- CWE-268
Affected products
| Vendor | Product |
|---|---|
| canonical | ubuntu_linux |
Description
Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2026-3888
- [Other]https://blog.qualys.com/vulnerabilities-threat-research/2026/03/17/cve-2026-3888-important-snap-flaw-enables-local-privilege-escalation-to-root
- [Other]https://cdn2.qualys.com/advisory/2026/03/17/snap-confine-systemd-tmpfiles.txt
- [Other]https://discourse.ubuntu.com/t/snapd-local-privilege-escalation-cve-2026-3888
- [Other]https://ubuntu.com/security/CVE-2026-3888
- [Other]https://ubuntu.com/security/notices/USN-8102-1
- [Other]http://www.openwall.com/lists/oss-security/2026/03/18/1
Related CVEs
Same vendor
- CVE-2026-47337 — Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket ... (3.3 LOW)
- CVE-2026-47336 — Ubuntu Linux 6.8 contains SAUCE patches with a possible use of an uninitialized variable in AppArmor AF_INET/AF_INET6 socket mediation code (3.3 LOW)
- CVE-2026-47335 — Ubuntu Linux 6.8 contains SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications (5.5 MEDIUM)
- CVE-2026-47334 — Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code (5.5 MEDIUM)
- CVE-2026-47333 — Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, l... (7.8 HIGH)
Same CWE
- CVE-2026-32325 — Privilege chaining issue exists in ServerView Agents for Windows V11.60.04 and earlier (7.8 HIGH)