snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local attacker to read information that should have been private. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1
During installation, installed file permissions are set to allow anyone to modify those files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Snapd | Canonical | * | 2.54.3 (excluding) |
Snapd | Ubuntu | bionic | * |
Snapd | Ubuntu | devel | * |
Snapd | Ubuntu | esm-infra/xenial | * |
Snapd | Ubuntu | focal | * |
Snapd | Ubuntu | groovy | * |
Snapd | Ubuntu | hirsute | * |
Snapd | Ubuntu | impish | * |
Snapd | Ubuntu | snap | * |
Snapd | Ubuntu | trusty/esm | * |
Snapd | Ubuntu | upstream | * |
Snapd | Ubuntu | xenial | * |