Executive brief
Canonical Livepatch is a service that allows Ubuntu systems to receive critical security updates without rebooting. A security flaw in the Livepatch software allows a standard user on a computer to steal a high-level security token. This token could allow an attacker to impersonate the system owner, access subscription services, or interfere with the Livepatch server.
Technical details
An improper access control vulnerability (CWE-306/CWE-732) exists in the canonical-livepatch snap client prior to version 10.15.0. The flaw resides in the livepatchd.sock Unix domain socket, which fails to properly authenticate or restrict requests. A local, unprivileged attacker can send a crafted request to this socket to retrieve a root-level authentication token. This exploit is only possible on systems where Livepatch has been enabled with a valid Ubuntu Pro subscription. The vulnerability has been patched in version 10.15.0.
Affected products
- Canonical Livepatch Client (Snap) < 10.15.0
Timeline
- 2026-04-20: disclosed
- 2026-04-20: advisory
- 2026-04-20: patched