Hi, The following vulnerabilities were published for snapd. CVE-2026-15226[0]: | A sandbox confinement bypass vulnerability exists in Canonical snapd | within its internal execution environment compiler (snap-confine). | The default seccomp security templates generated by the engine to | restrict system calls do not filter or reject process operations | capable of creating or manipulating file execution flags with set- | user-ID attributes. Consequently, an application running within a | strictly confined snap environment can successfully compile or drop | binaries and apply setuid properties to them. If a compromised or | malicious process inside the snap sandbox executes these generated | setuid binaries, it can potentially circumvent architectural | sandboxing assumptions, drop intended restriction policies, or | execute privileged actions inside the container namespace that | should otherwise be strictly blocked. The vulnerability has been | resolved by hardening the seccomp template engine to block the | execution and creation of setuid executables by sandboxed snap | processes. CVE-2024-5300[1]: | An access control bypass and information disclosure vulnerability | exists in the base AppArmor security profile configuration of | Canonical snapd. The abstraction rules located in | /etc/apparmor.d/abstractions/nss-systemd (inherited via ) | inadvertently permit strictly confined snap applications, which lack | the privileged account-control interface, to interact directly with | the io.systemd.Multiplexer and io.systemd.NameServiceSwitch UNIX | domain sockets under /run/systemd/userdb/. On systems where the | systemd-userdbd service is installed and operational, the service | fails to distinguish between an unconfined root user on the host | system and a restricted root user running within a snap | application's sandbox (such as a daemon or configuration hook). | Because systemd-userdbd returns "complete" user records—including | sensitive hashed user passwords from /etc/shadow—when queried by a | process running as root, a compromised or malicious strictly | confined snap executing code as root can successfully query the | Varlink interface to retrieve all system password hashes, bypassing | intended snap sandbox restrictions. This issue is mitigated by the | fact that systemd-userdbd is not installed by default on standard | Ubuntu deployments. CVE-2026-8933[2]: | A local privilege escalation vulnerability exists in snap-confine, a | set-capabilities core component used internally by Canonical snapd | to construct the secure execution environment for snap applications. | This vulnerability uniquely affects versions of snap-confine | configured with set-capabilities (rather than standard set-uid-root | installations). Due to a flaw in how privilege boundaries or | security sandboxes are initialized when the binary runs under | limited ambient capabilities, a local, unprivileged attacker can | exploit this behavior to bypass intended restrictions and execute | arbitrary code. Successful exploitation allows the local user to | elevate their privileges to full root authority. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-15226 https://www.cve.org/CVERecord?id=CVE-2026-15226 [1] https://security-tracker.debian.org/tracker/CVE-2024-5300 https://www.cve.org/CVERecord?id=CVE-2024-5300 [2] https://security-tracker.debian.org/tracker/CVE-2026-8933 https://www.cve.org/CVERecord?id=CVE-2026-8933 Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
snapd, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1142551@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Zygmunt Krynicki <me@zygoon.pl> (supplier of updated snapd package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 21 Aug 2026 10:45:42 +0000
Source: snapd
Architecture: source
Version: 2.76.3-1
Distribution: unstable
Urgency: medium
Maintainer: Zygmunt Krynicki <me@zygoon.pl>
Changed-By: Zygmunt Krynicki <me@zygoon.pl>
Closes: 1122720 1136588 1142551
Changes:
snapd (2.76.3-1) unstable; urgency=medium
.
[ Katie May ]
* New upstream release, LP: #2158301
- FDE: support keyboard configuration at install-time for first-boot
- FDE: re-enable passphrases/PINs at install-time
- FDE: require volumes authentication if HWROT is missing
- FDE: bump secboot to rev 457b03a16d19
- FDE: use new secboot API for reprovision TPM
- Cross-distro: modify SELinux policy to use
init_named_socket_activation() for allowing systemd to start snapd
through socket activation
- packaging: make sure that usr/bin/snap is built with correct build
tags on debian sid
- Ensure profiles are setup before running prepare-{slot, plug}*
hooks
.
[ Zygmunt Krynicki ]
* New upstream version 2.76.3
* Not annotated in the Ubuntu changelog but this fixes CVE-2026-15226
(Closes: #1142551)
* debian: add procps to Build-Depends for pidof (Closes: #1136588)
* debian: replace dbus with dbus-daemon in Build-Depends (Closes: #1122720)
* debian: restrict Architecture to known-working arches
* debian: make Zygmunt Krynicki the package maintainer
* debian: update Standards-Version to 4.7.4
Checksums-Sha1:
3c5d60dafc815aa30aed6242ce54276a9704d0cf 3627 snapd_2.76.3-1.dsc
6be0470c41000a6ed695514575ac4162e6f52e5f 8335920 snapd_2.76.3.orig.tar.xz
228138437688b7ef2f0570f1da0a502d2bb9135a 156196 snapd_2.76.3-1.debian.tar.xz
3745df00fd9540816956fa024fe194b0824b710a 13670 snapd_2.76.3-1_source.buildinfo
Checksums-Sha256:
3d0098a8df91a55a91e65caae34b9383f21f671d65fe97fe742643cd715b6d0d 3627 snapd_2.76.3-1.dsc
32456f3d05dd79e91bb8f60b8ea2a78f283a9de57c75af20ce8272607f29cf8b 8335920 snapd_2.76.3.orig.tar.xz
ec27ca821312188277dc86d3f61f71bae915467f3c0ebbc46374118bd49b321f 156196 snapd_2.76.3-1.debian.tar.xz
8c32f37865f6b16a7adddd9bf2342241b901191d538ed86d2b4c3f7de21c47c8 13670 snapd_2.76.3-1_source.buildinfo
Files:
5d443284dac60bef42e1aa3015f7e15a 3627 devel optional snapd_2.76.3-1.dsc
da3f436fece9ed115e3ede7c52b22c03 8335920 devel optional snapd_2.76.3.orig.tar.xz
0e8bb642fc3e7bea5e81e1fb7617ab7e 156196 devel optional snapd_2.76.3-1.debian.tar.xz
5b27fc7a519fa25aa63f7d6de7fe9e36 13670 devel optional snapd_2.76.3-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJIBAEBCgAyFiEEt2ztm0XK8VV9JxpqKJTpOijGe0cFAmqILJsUHHprcnluaWNr
aUBnbWFpbC5jb20ACgkQKJTpOijGe0fwgA//fqlGcl6xB/YdI8aeKOGZ6LCUITfu
SPh1EA/3IXhtOxj01mhoh0TVYt+6v8ozkw6Tv5OTqkK3saYdQ8zECKo0h1MOpeSt
iaoAF5ZgmQMaF2DPmqUSWdZM3PIymmuFmMJeEpdDZZRUSz83123r9JTcinNcbX5T
nI4EmWZHOMNRCboOUiAKaNuRpn9tV6Shb8ftkPGSr1f43QWfEpLKEssnqYCBCYpF
wOYAQzO46OI4lFfy9821xrycpWpfBklRcX64wDEIIJPlGudITts2rKozVwZBzp7v
K0ud2AKjPROIdWcAB9/NHJ6nzr2B/NU0jhS1m3KllNbl+cKPuP+SfSdnx0PAbc4v
tO50y0UV2qfhzGC2xVCS7naYHCUeTQbCeoxNf0la0m5oeTMtdfH50G5cbL3iewqP
cAoTXguebyyCNC0eVwwd4NBgrPgdrH9twAHh/JqnD82UmL7gbqmlMQ9FWgqg6tB1
YqzOKwi1KdKahak2PtUtBpN1QT6DqI5H0ydN3RSkE6ywvy7tERbHxY69cHaw9lr8
E5xiuy+oBru2SnKHtYxXwGwn/C+sHp3Zf+FwswUK/iA5V+u3d9rRSL5vL6ycSlBa
sCox/UmZWS9l0Rbeh492tzDMS/MGqQBGkVaF8udcd4beUCUqKqzd5SzBlvAd5fg/
HGvGLXW84JdmE0Q=
=MMcm
-----END PGP SIGNATURE-----