
A serious security vulnerability in standard Ubuntu Desktop installations from version 24.04 onward provides a path to gain root privileges.
Identified as CVE-2026-3888 (CVSS score: 7.8), this flaw could allow a threat actor to completely compromise an affected system.
“This vulnerability (CVE-2026-3888) enables a local, unprivileged attacker to achieve full root access by exploiting the interaction between two standard system components: snap-confine and systemd-tmpfiles,” stated the Qualys Threat Research Unit (TRU) in their report. “While exploitation depends on a specific time window (10–30 days), successful exploitation leads to total control of the compromised system.”
Qualys explained that the issue arises from an unintended interaction between snap-confine, which isolates snap application environments, and systemd-tmpfiles, which automatically removes temporary files and directories (like /tmp, /run, and /var/tmp) exceeding a defined age.
The vulnerability is resolved in the following versions:
The attack needs limited permissions and no user interaction, but is considered complex due to the time-based element in the exploit process.
“By default, systemd-tmpfiles is configured to remove outdated data in /tmp,” Qualys noted. “An attacker can exploit this by manipulating the timing of these cleanup operations.”
The attack unfolds as follows:
Qualys also noted a race condition in the uutils coreutils package. This can let local attackers without special privileges substitute directory entries with symbolic links (symlinks) during cron jobs executed as root.
“Exploiting this successfully may allow arbitrary file deletion as root or further privilege escalation by targeting snap sandbox directories,” stated the cybersecurity firm. “The vulnerability was reported and addressed before Ubuntu 25.10 was publicly released. The default rm command in Ubuntu 25.10 was switched back to GNU coreutils to address this risk immediately. Since then, upstream fixes have been added to the uutils repository.”
#access #admin #attackers. #cleanup #cve-2026-3888, #due #exploit #flaw #gain #news #root #systemd, #timing #ubuntu’s — News
© Bulletproof Servers. All rights reserved.