# CVE-2026-8933: Race Condition in Ubuntu snap-confine Enables Local Privilege Escalation to Root

> A dual race-condition (TOCTOU) vulnerability in Ubuntu's snap-confine sandbox launcher, introduced when Canonical hardened snap-confine from a set-uid-root binary to a set-capabilities model in July 2025, lets an unprivileged local user mount a malicious FUSE filesystem over a temporary scratch directory, inject symlinks, and drop a malicious udev rule to gain full root code execution. Discovered by Qualys TRU; publicly disclosed and patched July 21, 2026 with no reported in-the-wild exploitation.

- **Published:** 2026-07-22T00:00:00Z
- **Last reviewed:** 2026-07-25T23:02:58.499Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1633
- **ID:** TL-2026-1633
- **Severity:** HIGH (CVSS 7.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 29 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-8933

## Description

CVE-2026-8933 is a High-severity (CVSS 3.1: 7.8, AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) local privilege escalation vulnerability in snap-confine, the setuid/capabilities-based sandbox launcher that snapd uses to construct the confined execution environment for snap applications on Ubuntu. In July 2025, Canonical moved snap-confine away from a traditional set-uid-root binary model to a 'set-capabilities' model (retaining a narrow set of Linux capabilities such as CAP_SYS_ADMIN instead of full root) as a defense-in-depth hardening measure. That change inadvertently introduced a race-condition window during sandbox initialization.

When snap-confine prepares a snap's execution environment it creates a scratch directory under /tmp (e.g. /tmp/snap.rootfs_XXXXXX) that is briefly owned by the invoking unprivileged user before ownership is transferred to root via fchown(fd, 0, 0). Qualys TRU identified two concurrent, chainable race conditions in this window. First, an attacker mounts a malicious FUSE filesystem over the scratch directory immediately after its creation; because mount-namespace isolation is applied by snap-confine only later in the sequence, the FUSE mount remains externally accessible and can intercept/unmount snap-confine's subsequent operations. Second, when snap-confine opens files in that directory with open(full_path, O_CREAT|O_TRUNC, 0644) without the O_NOFOLLOW flag, an attacker-planted symlink causes the open() call to follow the link and write to an arbitrary attacker-chosen target instead of the intended sandbox file. A further permission-widening race (chmod 0666) can occur before the fchown() ownership transfer completes, extending the writable window.

To turn this arbitrary-write primitive into root code execution, the exploit targets /run/udev/**, a path that AppArmor's snap-confine security profile permits read-write access to. By redirecting the symlink race to write a malicious .rules file into /run/udev/rules.d/ and then triggering a FUSE mount/unmount cycle, the attacker causes systemd-udevd (which runs as root and processes udev events, including RUN+= directives in rule files) to execute an attacker-controlled command with full root privileges — completing the local privilege-escalation chain from unprivileged user to root with no user interaction and low attack complexity.

The flaw affects default installations of Ubuntu Desktop 22.04 LTS, 24.04 LTS, 25.10, and 26.04 running vulnerable snapd releases (approximately snapd 2.75.0 through 2.76.0) that use the set-capabilities snap-confine variant; systems still running the legacy set-uid-root snap-confine configuration are not affected. Qualys TRU (led by Saeed Abbasi) privately disclosed the issue to the Ubuntu Security Team on 2026-04-22; Canonical distributed fixes to the linux-distros coordination list on 2026-07-13 and published a public advisory on 2026-07-14, with full coordinated disclosure and patch release on 2026-07-21 via Ubuntu Security Notice USN-8579-1, which also bundled fixes for two related snapd flaws: CVE-2024-5300 (AppArmor template flaw exposing hashed user passwords via the systemd-userdbd varlink interface, affecting Ubuntu releases back to 16.04 LTS) and CVE-2026-15226 (seccomp template flaw permitting setuid binary creation, enabling escape from confined root to unconfined root). No in-the-wild exploitation or public PoC release has been reported for CVE-2026-8933 as of disclosure; Qualys withheld full working exploit code pending patch adoption. Given that snap is a default packaging format across most modern Ubuntu Desktop and Ubuntu Core installations, and that the vulnerability requires only unprivileged local code execution as a precondition (readily obtainable via a malicious downloaded binary, compromised low-privilege service account, or post-initial-access foothold), this issue warrants priority patching and detection coverage for privilege-escalation chains involving snap-confine, FUSE mounts, and udev rule file writes.

## MITRE ATT&CK

- T1068 Exploitation for Privilege Escalation
- T1548.001 Abuse Elevation Control Mechanism: Setuid and Setgid
- T1222.002 Linux and Mac Permissions
- T1211 Exploitation for Stealth
- T1546.017 Event Triggered Execution: Udev Rules
- T1059.004 Command and Scripting Interpreter: Unix Shell
- T1082 System Information Discovery
- T1518.001 Software Discovery: Security Software Discovery
- T1564.001 Hide Artifacts: Hidden Files and Directories
- T1036 Masquerading
- T1587.004 Develop Capabilities: Exploits
- T1548 Abuse Elevation Control Mechanism
- T1140 Deobfuscate/Decode Files or Information
- T1552 Unsecured Credentials
- T1078.003 Valid Accounts: Local Accounts
- T1611 Escape to Host
- T1569 System Services

## Sources

- [Ubuntu snap-confine flaw could give attackers root access](https://thehackernews.com/2026/07/ubuntu-snap-confine-flaw-could-give.html)
- [CVE-2026-8933: Local Privilege Escalation in Ubuntu snap-confine](https://blog.qualys.com/vulnerabilities-threat-research/2026/07/21/cve-2026-8933-snap-confine-local-privilege-escalation)
- [Qualys Security Advisory: snap-confine set-capabilities race condition](https://cdn2.qualys.com/advisory/2026/07/21/snap-confine-set-capabilities.txt)
- [USN-8579-1: snapd vulnerabilities](https://ubuntu.com/security/notices/USN-8579-1)
- [NVD - CVE-2026-8933](https://nvd.nist.gov/vuln/detail/CVE-2026-8933)
- [Ubuntu snap-confine Vulnerability Enables Local Root Access](https://www.infosecurity-magazine.com/news/ubuntu-snap-confine-local-root-cve/)
- [Three New Ubuntu Snap Vulnerabilities Made Public - One Dates Back To Ubuntu 16.04 LTS](https://www.phoronix.com/news/Ubuntu-Snap-Three-More-Vulns)
- [Snapd - multiple vulnerabilities fixed](https://discourse.ubuntu.com/t/snapd-multiple-vulnerabilities-fixed/85433)
- [How to Patch Ubuntu Snap Vulnerabilities (2026)](https://www.fosslinux.com/159314/patch-ubuntu-snap-vulnerabilities.htm)
- [Ubuntu snap-confine flaw can give attackers root access](https://securitybrief.co.uk/story/ubuntu-snap-confine-flaw-can-give-attackers-root-access)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1633
