Root exploit in Ubuntu’s systemd cleanup due to timing flaw (CVE-2026-3888). Attackers gain admin access.
Mar 19, 2026 // 16:03 - Niko Dunn


A serious security vulnerability in standard Ubuntu Desktop installations from version 24.04 onward provides a path to gain root privileges.

Identified as CVE-2026-3888 (CVSS score: 7.8), this flaw could allow a threat actor to completely compromise an affected system.

“This vulnerability (CVE-2026-3888) enables a local, unprivileged attacker to achieve full root access by exploiting the interaction between two standard system components: snap-confine and systemd-tmpfiles,” stated the Qualys Threat Research Unit (TRU) in their report. “While exploitation depends on a specific time window (10–30 days), successful exploitation leads to total control of the compromised system.” 

Qualys explained that the issue arises from an unintended interaction between snap-confine, which isolates snap application environments, and systemd-tmpfiles, which automatically removes temporary files and directories (like /tmp, /run, and /var/tmp) exceeding a defined age.

The vulnerability is resolved in the following versions:

  • Ubuntu 24.04 LTS – snapd versions before 2.73+ubuntu24.04.1
  • Ubuntu 25.10 LTS – snapd versions before 2.73+ubuntu25.10.1
  • Ubuntu 26.04 LTS (Dev) – snapd versions before 2.74.1+ubuntu26.04.1
  • Upstream snapd – versions prior to 2.75

The attack needs limited permissions and no user interaction, but is considered complex due to the time-based element in the exploit process.

“By default, systemd-tmpfiles is configured to remove outdated data in /tmp,” Qualys noted. “An attacker can exploit this by manipulating the timing of these cleanup operations.”

The attack unfolds as follows:

  • The attacker waits for the system’s cleanup service to delete a vital directory (/tmp/.snap) required by snap-confine. The standard waiting period is 30 days in Ubuntu 24.04 and 10 days in later releases.
  • After deletion, the attacker recreates the directory containing malicious code.
  • During the subsequent sandbox initialization, snap-confine bind mounts these files as root, enabling the execution of arbitrary code with elevated privileges.

Qualys also noted a race condition in the uutils coreutils package. This can let local attackers without special privileges substitute directory entries with symbolic links (symlinks) during cron jobs executed as root.

“Exploiting this successfully may allow arbitrary file deletion as root or further privilege escalation by targeting snap sandbox directories,” stated the cybersecurity firm. “The vulnerability was reported and addressed before Ubuntu 25.10 was publicly released. The default rm command in Ubuntu 25.10 was switched back to GNU coreutils to address this risk immediately. Since then, upstream fixes have been added to the uutils repository.”

#access  #admin  #attackers.  #cleanup  #cve-2026-3888,  #due  #exploit  #flaw  #gain  #news  #root  #systemd,  #timing  #ubuntu’s   —   News