Ubuntu: Systemd timing flaw (CVE-2026-3888) allows attackers to become root user.
Mar 18, 2026 // 13:23 - Norina Velotta


A serious security vulnerability exists in standard Ubuntu Desktop installations, versions 24.04 and later, that could allow someone to gain root access.

Identified as CVE-2026-3888 (CVSS score: 7.8), this vulnerability could give an attacker complete control over an affected system.

“This flaw (CVE-2026-3888) allows a local user with limited permissions to gain full root privileges through the interaction of two standard system components: snap-confine and systemd-tmpfiles,” stated the Qualys Threat Research Unit (TRU) . “While exploiting this requires a wait of 10 to 30 days, the impact is a complete system compromise.”

Qualys explains that the issue arises from how snap-confine, which isolates snap applications, and systemd-tmpfiles, which automatically removes old temporary files and directories (like /tmp, /run, and /var/tmp), interact with each other.

The vulnerability has been fixed in the following versions:

  • Ubuntu 24.04 LTS – snapd versions before 2.73+ubuntu24.04.1
  • Ubuntu 25.10 LTS – snapd versions before 2.73+ubuntu25.10.1
  • Ubuntu 26.04 LTS (Dev) – snapd versions before 2.74.1+ubuntu26.04.1
  • Upstream snapd – versions before 2.75

The attack requires minimal permissions and no user interaction, but is considered complex due to the waiting period involved.

“By default, systemd-tmpfiles is set to delete old files in /tmp,” Qualys said. “An attacker can exploit this by manipulating when these cleanups occur.”

The attack unfolds as follows:

  • The attacker must wait for the system’s cleanup process to delete a critical directory (/tmp/.snap) required by snap-confine. The delay is 30 days in Ubuntu 24.04 and 10 days in later versions.
  • Once deleted, the attacker recreates the directory containing manipulated, malicious content.
  • When snap-confine initializes the sandbox, it bind mounts the manipulated files as root, allowing the attacker to run arbitrary code with those elevated privileges.

Qualys also found a race condition vulnerability in the uutils coreutils package allowing an unprivileged local user to replace directory entries with symbolic links (symlinks) during cron jobs run as root.

“Successful exploitation could lead to arbitrary file deletion as root or further privilege escalation by targeting snap sandbox directories,” states the cybersecurity company, “The vulnerability was reported and mitigated before Ubuntu 25.10’s public release by reverting to GNU coreutils’ rm command to address the immediate risk. Fixes for the uutils repository have since been implemented upstream.”

#allows  #attackers.  #become  #cve-2026-3888,  #flaw  #news  #root  #systemd,  #timing  #ubuntu,  #user   —   News