CVE

CVE-2024-29068

Severity:
MEDIUM
Type:
Unavailable / Other
Publication date:
25/07/2024
Last modified:
26/08/2024

Description

In snapd versions prior to 2.62, snapd failed to properly check the file<br /> type when extracting a snap. The snap format is a squashfs file-system<br /> image and so can contain files that are non-regular files (such as pipes <br /> or sockets etc). Various file entries within the snap squashfs image<br /> (such as icons etc) are directly read by snapd when it is extracted. An <br /> attacker who could convince a user to install a malicious snap which<br /> contained non-regular files at these paths could then cause snapd to block<br /> indefinitely trying to read from such files and cause a denial of service.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:canonical:snapd:*:*:*:*:*:*:*:* 2.62 (excluding)