Executive brief
A security flaw in the AppArmor configuration for Canonical snapd allows restricted applications to bypass sandbox protections. If a malicious application is installed as a 'snap' and gains administrative privileges within its own container, it can steal sensitive system password hashes from the host computer. This could allow an attacker to perform offline password cracking to gain full control over other user accounts on the system.
Technical details
An access control bypass exists in the AppArmor abstraction rules for nss-systemd within Canonical snapd. The vulnerability stems from rules in /etc/apparmor.d/abstractions/nss-systemd that inadvertently allow strictly confined snaps to communicate with io.systemd.Multiplexer and io.systemd.NameServiceSwitch UNIX domain sockets. When the systemd-userdbd service is active, it fails to differentiate between host-level root users and restricted root users within a snap sandbox. A malicious snap running as root can query the Varlink interface to retrieve complete user records, including sensitive hashed passwords from /etc/shadow. This issue is mitigated by the fact that systemd-userdbd is not installed by default on standard Ubuntu deployments. Patches are available in snapd version 2.76.1 and corresponding Ubuntu package updates.
Affected products
- Canonical snapd before 2.76.1
- Canonical Ubuntu 26.04 LTS before 2.76+ubuntu26.04.3
- Canonical Ubuntu 24.04 LTS before 2.76+ubuntu24.04.1
- Canonical Ubuntu 22.04 LTS before 2.76+ubuntu22.04.1
- Canonical Ubuntu 20.04 LTS before 2.67.1+20.04ubuntu1~esm2
Timeline
- 2026-07-21: advisory
- 2026-07-21: disclosed