Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-5300— AppArmor Base Profile Misconfiguration in snapd Permits Confined Snaps Unauthorized Access to Hashed Passwords via systemd-userdbd

CVSS 5.6 · Medium EPSS 0.10% · P1

Affected Version Matrix 7

VendorProductVersion RangeStatus
NoneNone< 2.76.1affected
CanonicalUbuntu 16.04 LTS2.61.4ubuntu0.16.04.1+esm3unaffected
CanonicalUbuntu 18.04 LTS2.61.4ubuntu0.18.04.1+esm3unaffected
CanonicalUbuntu 20.04 LTS2.67.1+20.04ubuntu1~esm2unaffected
CanonicalUbuntu 22.04 LTS2.76+ubuntu22.04.1unaffected
CanonicalUbuntu 24.04 LTS2.76+ubuntu24.04.1unaffected
CanonicalUbuntu 26.04 LTS2.76+ubuntu26.04.3unaffected

I. Basic Information for CVE-2024-5300

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
AppArmor Base Profile Misconfiguration in snapd Permits Confined Snaps Unauthorized Access to Hashed Passwords via systemd-userdbd
Source: CVE Program / CVE List V5
Vulnerability Description
An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules located in /etc/apparmor.d/abstractions/nss-systemd (inherited via ) inadvertently permit strictly confined snap applications, which lack the privileged account-control interface, to interact directly with the io.systemd.Multiplexer and io.systemd.NameServiceSwitch UNIX domain sockets under /run/systemd/userdb/. On systems where the systemd-userdbd service is installed and operational, the service fails to distinguish between an unconfined root user on the host system and a restricted root user running within a snap application's sandbox (such as a daemon or configuration hook). Because systemd-userdbd returns "complete" user records—including sensitive hashed user passwords from /etc/shadow—when queried by a process running as root, a compromised or malicious strictly confined snap executing code as root can successfully query the Varlink interface to retrieve all system password hashes, bypassing intended snap sandbox restrictions. This issue is mitigated by the fact that systemd-userdbd is not installed by default on standard Ubuntu deployments.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
敏感数据的不恰当跨边界移除
Source: CVE Program / CVE List V5
Vulnerability Title
Canonical snapd 信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Canonical snapd是英国Canonical公司开源的一个跨平台包管理工具。 Canonical snapd 2.76.1之前版本存在信息泄露漏洞,该漏洞源于基础AppArmor安全配置文件配置中的访问控制绕过和信息泄露问题,导致严格受限的snap应用可与UNIX域套接字直接交互,并利用systemd-userdbd服务无法区分主机系统上的无限制root用户和snap应用沙箱中的受限root用户,通过查询Varlink接口检索所有系统密码哈希,绕过snap沙箱限制。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-- 0 ~ 2.76.1 -
CanonicalUbuntu 26.04 LTS 2.76+ubuntu26.04.3 -
CanonicalUbuntu 24.04 LTS 2.76+ubuntu24.04.1 -
CanonicalUbuntu 22.04 LTS 2.76+ubuntu22.04.1 -
CanonicalUbuntu 20.04 LTS 2.67.1+20.04ubuntu1~esm2 -
CanonicalUbuntu 18.04 LTS 2.61.4ubuntu0.18.04.1+esm3 -
CanonicalUbuntu 16.04 LTS 2.61.4ubuntu0.16.04.1+esm3 -

II. Public POCs for CVE-2024-5300

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-5300

登录查看更多情报信息。

Vendor Advisories for CVE-2024-5300 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2024-5300

No comments yet


Leave a comment