GHSA-p9v8-q5m4-pf46
HIGHCVE-2024-5138A snap with prior permissions to create a mount entry on the host, such as firefox, normally uses the permission from one of the per-snap hook programs. A unprivileged users cannot normally trigger that behaviour by using snap run --shell firefox followed by snapctl mount, since snapd validates the requesting user identity (root or non-root). The issue allows unprivileged users to bypass that chec
- Affected
- >=0
- Fixed in
- 2.63.1
- Published
- 2025-01-16
- Source
- github