- Sources: Qualys writeup, r/linux discussion
- Summary: Qualys disclosed CVE-2026-8933 on 2026-07-21, a local privilege escalation to root in the snap-confine sandbox helper on Ubuntu Desktop 24.04, 25.10, and 26.04. The flaw chains two race conditions during sandbox setup: a window where a temporary directory is owned by the calling user before ownership transfers to root, and symlink manipulation that redirects a privileged write to an arbitrary target. Qualys attributes the exposure to a hardening change from set-uid-root to set-capabilities, which leaves snap-confine running with the caller's effective UID while retaining near-root capabilities. Canonical released fixed snapd packages through the Ubuntu Security Team, and Qualys states a proof of concept accompanies the advisory with no active exploitation reported.
- Why it matters: snap-confine runs on default Ubuntu desktop installs, so a local-root chain there is broadly reachable on developer and CI machines, continuing a run of high-value Linux privilege-escalation disclosures.
- Follow-up: Watch for a weaponized exploit beyond the PoC, backports across supported Ubuntu releases, and any CISA KEV addition.
send feedback on this story