Home

Timing Flaw in systemd Cleanup Enables Root Privilege Escalation

$$21228
https://toast.ooo/u/cm0002 posted on Apr 1, 2026 13:00

Yet another critical vulnerability in systemd, this time involving snapd. Ubuntu folk are affected.

“A serious security issue has been discovered in Ubuntu, and it is gaining attention in the cybersecurity community. The vulnerability is identified as CVE-2026-3888 and mainly affects Ubuntu Desktop systems from version 24.04 onwards. This flaw is dangerous because it allows an attacker with limited access to gain full root privileges. Root access means complete control over the entire system.”

https://toast.ooo/post/13117714
Reply
$$21249
https://lemmy.dbzer0.com/u/ChaosMonkey posted on Apr 1, 2026 14:23
In reply to: https://toast.ooo/post/13117714

Oh snap!

https://lemmy.dbzer0.com/comment/25291974
Reply
$$21315
https://lemmy.blahaj.zone/u/randamumaki posted on Apr 1, 2026 18:22
In reply to: https://toast.ooo/post/13117714

Why did people move away from sysvinit again?

https://lemmy.blahaj.zone/comment/19891817
Reply
$$21316
https://piefed.social/u/eleijeep posted on Apr 1, 2026 18:32
In reply to: https://toast.ooo/post/13117714

https://blog.qualys.com/vulnerabilities-threat-research/2026/03/17/cve-2026-3888-important-snap-flaw-enables-local-privilege-escalation-to-root

https://piefed.social/comment/10783603
Reply
$$21319
https://lemmy.zip/u/LiveLM posted on Apr 1, 2026 18:45
In reply to: https://lemmy.blahaj.zone/comment/19891817

Reading the post, the issue is more on Snap’s side and the way Ubuntu configures it than on SystemD…

https://lemmy.zip/comment/25635291
Reply
$$21353
https://lemmy.blahaj.zone/u/randamumaki posted on Apr 1, 2026 20:18
In reply to: https://lemmy.zip/comment/25635291

Ah, well, yet another mark against using snap then. My bad. Thanks for letting me know. :)

https://lemmy.blahaj.zone/comment/19896105
Reply
$$21373
https://feddit.org/u/30p87 posted on Apr 1, 2026 21:21
In reply to: https://lemmy.zip/comment/25635291

And that’s why you use at least very basic owner/group and mod permission validation on internal files

https://feddit.org/comment/12331675
Reply