
A serious security vulnerability exists in standard Ubuntu Desktop installations, versions 24.04 and later, that could allow someone to gain root access.
Identified as CVE-2026-3888 (CVSS score: 7.8), this vulnerability could give an attacker complete control over an affected system.
“This flaw (CVE-2026-3888) allows a local user with limited permissions to gain full root privileges through the interaction of two standard system components: snap-confine and systemd-tmpfiles,” stated the Qualys Threat Research Unit (TRU) . “While exploiting this requires a wait of 10 to 30 days, the impact is a complete system compromise.”
Qualys explains that the issue arises from how snap-confine, which isolates snap applications, and systemd-tmpfiles, which automatically removes old temporary files and directories (like /tmp, /run, and /var/tmp), interact with each other.
The vulnerability has been fixed in the following versions:
The attack requires minimal permissions and no user interaction, but is considered complex due to the waiting period involved.
“By default, systemd-tmpfiles is set to delete old files in /tmp,” Qualys said. “An attacker can exploit this by manipulating when these cleanups occur.”
The attack unfolds as follows:
Qualys also found a race condition vulnerability in the uutils coreutils package allowing an unprivileged local user to replace directory entries with symbolic links (symlinks) during cron jobs run as root.
“Successful exploitation could lead to arbitrary file deletion as root or further privilege escalation by targeting snap sandbox directories,” states the cybersecurity company, “The vulnerability was reported and mitigated before Ubuntu 25.10’s public release by reverting to GNU coreutils’ rm command to address the immediate risk. Fixes for the uutils repository have since been implemented upstream.”
#allows #attackers. #become #cve-2026-3888, #flaw #news #root #systemd, #timing #ubuntu, #user — News
© Bulletproof Servers. All rights reserved.