Executive brief
qSnapper is a graphical tool used to manage Btrfs filesystem snapshots on Linux systems. A security flaw allows a local user to trick the system into using malicious configuration files by manipulating file paths. This could allow an attacker to crash the service, access sensitive system information, or potentially gain full administrative (root) control over the computer.
Technical details
A path traversal vulnerability exists in the D-Bus service of qSnapper due to insufficient validation of the 'configName' parameter. This parameter is passed to libsnapper without sanitization, allowing an attacker to use '../' sequences to reference arbitrary files on the filesystem as configuration files. Depending on the specific D-Bus method invoked, a local attacker can cause a denial of service (by pointing to device files like /dev/zero), leak sensitive information by forcing the parser to read files like /etc/shadow, or achieve privilege escalation when combined with other vulnerabilities like Polkit authentication bypasses. The issue is fixed in version 1.3.3 by implementing strict allowlist validation for configuration names.
Affected products
- presire qSnapper before 1.3.3
Timeline
- 2026-04-10: disclosed: Initial discovery by SUSE security team
- 2026-05-25: patched: Upstream version 1.3.3 released
- 2026-06-22: advisory: NVD and SUSE public disclosure