• DMCA
  • Disclaimer
  • Terms and Conditions
  • Cookie Privacy Policy
  • Privacy Policy
  • Contact
  • Advertise
  • Home
  • Review
    In Africa, Kenyan startups have so far recorded highest funding growth this year – TechCrunch

    In Africa, Kenyan startups have so far recorded highest funding growth this year – TechCrunch

    Game firms request India PM Modi ‘uniform and fair treatment to all’ following BGMI ban – TechCrunch

    Game firms request India PM Modi ‘uniform and fair treatment to all’ following BGMI ban – TechCrunch

    WhatsApp extends time limit to delete a message to 60 hours – TechCrunch

    WhatsApp extends time limit to delete a message to 60 hours – TechCrunch

    Hold-outs targeted in fresh batch of noyb GDPR cookie consent complaints – TechCrunch

    Hold-outs targeted in fresh batch of noyb GDPR cookie consent complaints – TechCrunch

    Snapchat officially introduces parental controls through a new ‘Family Center’ feature – TechCrunch

    Snapchat officially introduces parental controls through a new ‘Family Center’ feature – TechCrunch

    Accel backs Produze to help agri-producers in India export globally – TechCrunch

    Accel backs Produze to help agri-producers in India export globally – TechCrunch

  • Gaming
    Brace Yourselves, A Pac-Man Live-Action Movie Is Currently In Development

    Brace Yourselves, A Pac-Man Live-Action Movie Is Currently In Development

    Sonic The Hedgehog 3 Film Now Has An Official Release Date

    Sonic The Hedgehog 3 Film Now Has An Official Release Date

    This Week’s Deals with Gold and Spotlight Sale (Week of August 8)

    This Week’s Deals with Gold and Spotlight Sale (Week of August 8)

    Mario Kart Tour Teases September Multiplayer Update, Will Add “New Ways To Play”

    Mario Kart Tour Teases September Multiplayer Update, Will Add “New Ways To Play”

    Marvel’s XCOM-Like Tactics Game Midnight Suns Delayed Again

    Marvel’s XCOM-Like Tactics Game Midnight Suns Delayed Again

    Sonic 3 Movie Locks In December 2024 Release Date

    Sonic 3 Movie Locks In December 2024 Release Date

  • Gear
    • All
    • Audio
    • Camera
    • Laptop
    • Smartphone
    BeDJ: A Step By Step Timestamped Guide For Learning How To DJ?

    BeDJ: A Step By Step Timestamped Guide For Learning How To DJ?

    Daily Authority: 📱 OnePlus and Oppo’s German ousting

    Daily Authority: 📱 OnePlus and Oppo’s German ousting

    IK Multimedia Beat Machines review: 100 vintage analogue drum machines brought into the 21st century

    IK Multimedia Beat Machines review: 100 vintage analogue drum machines brought into the 21st century

    iOS 16 beta 5 brings back battery percentage to the status bar

    iOS 16 beta 5 brings back battery percentage to the status bar

    Apple may be working on a HomePod rival for Amazon’s Echo Show

    Apple may be working on a HomePod rival for Amazon’s Echo Show

    Sennheiser MOMENTUM 4 Noise-Canceling Wireless Over-Ear Headphones

    Sennheiser MOMENTUM 4 Noise-Canceling Wireless Over-Ear Headphones

    Trending Tags

    • Best iPhone 7 deals
    • Apple Watch 2
    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • iOS 10
    • iPhone 7
    • Sillicon Valley
  • Computers
    Fractal Design Define 7 Nano, For The ITX Lover

    Fractal Design Define 7 Nano, For The ITX Lover

    Oh Ya, Netflix Did Get Into Games

    Oh Ya, Netflix Did Get Into Games

    Workstream – Monoprice’s Heavy Duty Gas Spring Desk Mount For A Single 32″ To 49″ Monitor

    Workstream – Monoprice’s Heavy Duty Gas Spring Desk Mount For A Single 32″ To 49″ Monitor

    Podcast #688 – Intel & AMD Financials, Ryzen 7000 Date, be quiet! Pure Base 500 FX, Sonos, 0-Day Hacks + MORE!

    Podcast #688 – Intel & AMD Financials, Ryzen 7000 Date, be quiet! Pure Base 500 FX, Sonos, 0-Day Hacks + MORE!

    AMD’s Raphael Might Have Come Out Of It’s Shell

    AMD’s Raphael Might Have Come Out Of It’s Shell

    Alder Lake-P and Cezanne UCFF Faceoff

    Alder Lake-P and Cezanne UCFF Faceoff

  • Applications
    Sony’s AirPods Pro alternatives are  off at Amazon

    Sony’s AirPods Pro alternatives are $50 off at Amazon

    Chinese Hackers Targeted Dozens of Industrial Enterprises and Public Institutions

    Chinese Hackers Targeted Dozens of Industrial Enterprises and Public Institutions

    Google Search goes down worldwide on Monday night

    Google Search goes down worldwide on Monday night

    Apple’s pace of acquisitions is at a record low

    Apple’s pace of acquisitions is at a record low

    HBO Max app finally supports this fun iPhone and iPad feature

    HBO Max app finally supports this fun iPhone and iPad feature

    Apple announces Missed Fortune, a new original podcast about a real-life treasure hunt

    Apple announces Missed Fortune, a new original podcast about a real-life treasure hunt

  • Security
    Are SASE and Zero Trust the key for manufacturers grappling with IoT cyber risks?

    Are SASE and Zero Trust the key for manufacturers grappling with IoT cyber risks?

    Smishing Attack Led to Major Twilio Breach

    Smishing Attack Led to Major Twilio Breach

    Number of Firms Unable to Access Cyber-Insurance Set to Double

    Number of Firms Unable to Access Cyber-Insurance Set to Double

    10 Malicious Code Packages Slither into PyPI Registry

    10 Malicious Code Packages Slither into PyPI Registry

    Live at Black Hat USA 2022

    Live at Black Hat USA 2022

    Ransomware, email compromise are top security threats, but deepfakes increase

    Ransomware, email compromise are top security threats, but deepfakes increase

No Result
View All Result
  • Home
  • Review
    In Africa, Kenyan startups have so far recorded highest funding growth this year – TechCrunch

    In Africa, Kenyan startups have so far recorded highest funding growth this year – TechCrunch

    Game firms request India PM Modi ‘uniform and fair treatment to all’ following BGMI ban – TechCrunch

    Game firms request India PM Modi ‘uniform and fair treatment to all’ following BGMI ban – TechCrunch

    WhatsApp extends time limit to delete a message to 60 hours – TechCrunch

    WhatsApp extends time limit to delete a message to 60 hours – TechCrunch

    Hold-outs targeted in fresh batch of noyb GDPR cookie consent complaints – TechCrunch

    Hold-outs targeted in fresh batch of noyb GDPR cookie consent complaints – TechCrunch

    Snapchat officially introduces parental controls through a new ‘Family Center’ feature – TechCrunch

    Snapchat officially introduces parental controls through a new ‘Family Center’ feature – TechCrunch

    Accel backs Produze to help agri-producers in India export globally – TechCrunch

    Accel backs Produze to help agri-producers in India export globally – TechCrunch

  • Gaming
    Brace Yourselves, A Pac-Man Live-Action Movie Is Currently In Development

    Brace Yourselves, A Pac-Man Live-Action Movie Is Currently In Development

    Sonic The Hedgehog 3 Film Now Has An Official Release Date

    Sonic The Hedgehog 3 Film Now Has An Official Release Date

    This Week’s Deals with Gold and Spotlight Sale (Week of August 8)

    This Week’s Deals with Gold and Spotlight Sale (Week of August 8)

    Mario Kart Tour Teases September Multiplayer Update, Will Add “New Ways To Play”

    Mario Kart Tour Teases September Multiplayer Update, Will Add “New Ways To Play”

    Marvel’s XCOM-Like Tactics Game Midnight Suns Delayed Again

    Marvel’s XCOM-Like Tactics Game Midnight Suns Delayed Again

    Sonic 3 Movie Locks In December 2024 Release Date

    Sonic 3 Movie Locks In December 2024 Release Date

  • Gear
    • All
    • Audio
    • Camera
    • Laptop
    • Smartphone
    BeDJ: A Step By Step Timestamped Guide For Learning How To DJ?

    BeDJ: A Step By Step Timestamped Guide For Learning How To DJ?

    Daily Authority: 📱 OnePlus and Oppo’s German ousting

    Daily Authority: 📱 OnePlus and Oppo’s German ousting

    IK Multimedia Beat Machines review: 100 vintage analogue drum machines brought into the 21st century

    IK Multimedia Beat Machines review: 100 vintage analogue drum machines brought into the 21st century

    iOS 16 beta 5 brings back battery percentage to the status bar

    iOS 16 beta 5 brings back battery percentage to the status bar

    Apple may be working on a HomePod rival for Amazon’s Echo Show

    Apple may be working on a HomePod rival for Amazon’s Echo Show

    Sennheiser MOMENTUM 4 Noise-Canceling Wireless Over-Ear Headphones

    Sennheiser MOMENTUM 4 Noise-Canceling Wireless Over-Ear Headphones

    Trending Tags

    • Best iPhone 7 deals
    • Apple Watch 2
    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • iOS 10
    • iPhone 7
    • Sillicon Valley
  • Computers
    Fractal Design Define 7 Nano, For The ITX Lover

    Fractal Design Define 7 Nano, For The ITX Lover

    Oh Ya, Netflix Did Get Into Games

    Oh Ya, Netflix Did Get Into Games

    Workstream – Monoprice’s Heavy Duty Gas Spring Desk Mount For A Single 32″ To 49″ Monitor

    Workstream – Monoprice’s Heavy Duty Gas Spring Desk Mount For A Single 32″ To 49″ Monitor

    Podcast #688 – Intel & AMD Financials, Ryzen 7000 Date, be quiet! Pure Base 500 FX, Sonos, 0-Day Hacks + MORE!

    Podcast #688 – Intel & AMD Financials, Ryzen 7000 Date, be quiet! Pure Base 500 FX, Sonos, 0-Day Hacks + MORE!

    AMD’s Raphael Might Have Come Out Of It’s Shell

    AMD’s Raphael Might Have Come Out Of It’s Shell

    Alder Lake-P and Cezanne UCFF Faceoff

    Alder Lake-P and Cezanne UCFF Faceoff

  • Applications
    Sony’s AirPods Pro alternatives are  off at Amazon

    Sony’s AirPods Pro alternatives are $50 off at Amazon

    Chinese Hackers Targeted Dozens of Industrial Enterprises and Public Institutions

    Chinese Hackers Targeted Dozens of Industrial Enterprises and Public Institutions

    Google Search goes down worldwide on Monday night

    Google Search goes down worldwide on Monday night

    Apple’s pace of acquisitions is at a record low

    Apple’s pace of acquisitions is at a record low

    HBO Max app finally supports this fun iPhone and iPad feature

    HBO Max app finally supports this fun iPhone and iPad feature

    Apple announces Missed Fortune, a new original podcast about a real-life treasure hunt

    Apple announces Missed Fortune, a new original podcast about a real-life treasure hunt

  • Security
    Are SASE and Zero Trust the key for manufacturers grappling with IoT cyber risks?

    Are SASE and Zero Trust the key for manufacturers grappling with IoT cyber risks?

    Smishing Attack Led to Major Twilio Breach

    Smishing Attack Led to Major Twilio Breach

    Number of Firms Unable to Access Cyber-Insurance Set to Double

    Number of Firms Unable to Access Cyber-Insurance Set to Double

    10 Malicious Code Packages Slither into PyPI Registry

    10 Malicious Code Packages Slither into PyPI Registry

    Live at Black Hat USA 2022

    Live at Black Hat USA 2022

    Ransomware, email compromise are top security threats, but deepfakes increase

    Ransomware, email compromise are top security threats, but deepfakes increase

No Result
View All Result
No Result
View All Result
Home Security

Dangerous privilege escalation bugs found in Linux package manager Snap

RealHacker Staff by RealHacker Staff
February 27, 2022
Dangerous privilege escalation bugs found in Linux package manager Snap
Share on FacebookShare on Twitter


Researchers discovered an easy-to-exploit vulnerability in Snap, a common utility packaging and distribution system developed for Ubuntu however accessible on a number of Linux distributions. The flaw permits a low-privileged consumer to execute malicious code as root, the best administrative account on Linux.

The vulnerability, tracked as CVE-2021-44731, is a part of a collection of flaws that researchers from safety agency Qualys present in numerous Linux elements whereas investigating the safety of Snap. This newest one, together with a separate difficulty tracked as CVE-2021-44730, are in snap-confine, the instrument chargeable for organising Snap utility sandboxes.

What’s Snap?

Snap is a package deal supervisor for Linux methods that was developed by Canonical, the corporate behind the favored Ubuntu desktop and server distribution. It permits the packaging and distribution of self-contained functions referred to as “snaps” that run inside a restricted container, offering a configurable stage of safety.

By being self-contained, Snap functions do not have exterior dependencies, which permits them to work cross-platform or cross-distribution. Historically, every main Linux distribution maintains its personal pre-packaged software program repository and software program supervisor. Debian has DEB, Ubuntu has PPA, Fedora and Crimson Hat have RPM, Arch Linux has Pacman, and so forth. All these methods pull within the desired package deal together with all different dependencies as separate packages. Snaps, however, come bundled with all of the wanted dependencies, making them universally deployable on all Linux methods which have the Snap service.

Snap ships by default on Ubuntu and several other Linux distributions and is offered as an choice in lots of others, together with the most important ones. It is used to distribute not solely desktop functions, but in addition cloud and IoT ones.

Snap confinement — the isolation function — has three ranges of safety with the Strict mode being utilized by most functions. On this mode, functions must request entry to entry information, different processes, or the community. This isn’t not like the appliance sandboxing and permissions mannequin from cellular working methods like Android.

Since utility sandboxing is among the core options of Snap, any privilege escalation vulnerability that permits escaping that isolation and taking management of the host system is taken into account very severe.

Privilege escalation flaws

The Qualys researchers have dubbed their two snap-confine vulnerabilities as “Oh Snap! Extra Lemmings” as a result of they observe one other privilege escalation flaw found in Snap in 2019 and dubbed Soiled Sock. Since Soiled Sock, Snap has seen an intensive safety audit by the SUSE safety staff and generally is programmed very defensively, making use of many kernel safety features similar to AppArmor profiles, seccomp filters and mount namespaces.

“We nearly deserted our audit after a couple of days,” the Qualys researchers stated of their advisory, including that “discovering and exploiting a vulnerability in snap-confine has been extraordinarily difficult (particularly in a default set up of Ubuntu).”

Nonetheless, the staff noticed a couple of minor bugs and determined to push on. This resulted within the discovery of two privilege escalation vulnerabilities: CVE-2021-44730, a hardlink assault that is solely exploitable in non-default configurations, specifically when the kernel’s fs.protected_hardlinks is 0; and CVE-2021-44731, a race situation that’s exploitable in default installations of Ubuntu Desktop and near-default installations of Ubuntu Server.

“This race situation opens up a world of prospects: Contained in the snap’s mount namespace (which we are able to enter by way of snap-confine itself), we are able to bind-mount a world-writable, non-sticky listing onto /tmp, or we are able to bind-mount every other a part of the filesystem onto /tmp,” the Qualys researchers stated. “We will reliably win this race situation, by monitoring /tmp/snap.lxd with inotify, by pinning our exploit and snap-confine to the identical CPU with sched_setaffinity(), and by reducing snap-confine’s scheduling precedence with setpriority() and sched_setscheduler().”

Within the technique of investigating these flaws, the Qualys researchers have additionally found bugs in different associated libraries and elements that Snap makes use of: Unauthorized unmounts in util-linux’s libmount (CVE-2021-3996 and CVE-2021-3995); surprising return worth from glibc’s realpath() (CVE-2021-3998); off-by-one buffer overflow/underflow in glibc’s getcwd() (CVE-2021-3999); Uncontrolled recursion in systemd’s systemd-tmpfiles (CVE-2021-3997). These flaws had been patched in these respective elements earlier this yr.

Ubuntu has launched patches for CVE-2021-44731 and CVE-2021-44730 for many of its supported Linux editions, aside from 16.04 ESM (Prolonged Safety Upkeep) which continues to be awaiting a repair. Each vulnerabilities are rated as excessive severity.

Copyright © 2022 IDG Communications, Inc.



Source link

Related

Tags: BugsDangerousescalationLinuxmanagerpackageprivilegeSnap
RealHacker Staff

RealHacker Staff

Recent Posts

  • Are SASE and Zero Trust the key for manufacturers grappling with IoT cyber risks?
  • In Africa, Kenyan startups have so far recorded highest funding growth this year – TechCrunch
  • Sony’s AirPods Pro alternatives are $50 off at Amazon
  • Smishing Attack Led to Major Twilio Breach
  • Brace Yourselves, A Pac-Man Live-Action Movie Is Currently In Development
  • BeDJ: A Step By Step Timestamped Guide For Learning How To DJ?
  • Game firms request India PM Modi ‘uniform and fair treatment to all’ following BGMI ban – TechCrunch
  • Daily Authority: 📱 OnePlus and Oppo’s German ousting

Follow Us

Categories

  • Applications
  • Audio
  • Camera
  • Computers
  • Gaming
  • Gear
  • Laptop
  • Metaverse
  • Microsoft
  • Photography
  • Review
  • Security
  • Smartphone
  • Uncategorized

Recent News

Are SASE and Zero Trust the key for manufacturers grappling with IoT cyber risks?

Are SASE and Zero Trust the key for manufacturers grappling with IoT cyber risks?

August 9, 2022
In Africa, Kenyan startups have so far recorded highest funding growth this year – TechCrunch

In Africa, Kenyan startups have so far recorded highest funding growth this year – TechCrunch

August 9, 2022
  • DMCA
  • Disclaimer
  • Terms and Conditions
  • Cookie Privacy Policy
  • Privacy Policy
  • Contact
  • Advertise

© 2019 - theme develop by real hacker news.

No Result
View All Result
  • Home
  • Review
  • Gaming
  • Gear
  • Computers
  • Applications
  • Security

© 2019 - theme develop by real hacker news.

error: Content is protected !!