Executive brief
qSnapper is a graphical tool used to manage Btrfs system snapshots on Linux. A security flaw in its background service allows a standard user to perform restricted administrative actions, such as deleting snapshots or rolling back the system to a previous state, if another authorized user has recently performed similar tasks. This could lead to unauthorized system changes or data loss by bypassing intended security prompts.
Technical details
The qSnapper D-Bus service (qsnapper-dbus-service) implemented an 'm_authenticated' boolean flag to cache Polkit authentication results. This flag was shared across the service instance rather than being scoped to a specific D-Bus caller or session. Consequently, if a privileged user successfully authenticates for an action like 'delete-snapshot', the flag is set to true, allowing any other local user (including unprivileged accounts like 'nobody') to call sensitive methods such as RestoreFiles() or DeleteSnapshot() without further Polkit intervention. Additionally, the service incorrectly treated authentication for one Polkit action as valid for others (e.g., 'delete-snapshot' granting 'rollback-snapshot' rights). The vulnerability is resolved in version 1.3.3 by removing the internal cache and relying on Polkit's native 'auth_admin_keep' mechanism.
Affected products
- presire qSnapper 1.2.1 to 1.3.2
Timeline
- 2026-04-16: disclosed: Vulnerability reported to upstream by SUSE security team
- 2026-05-25: patched: Upstream release v1.3.3 published with fixes
- 2026-06-22: advisory: CVE-2026-41049 published