Debian Package Tracker
Register | Log in
Subscribe

snapd

Daemon and tooling that enable snap packages

Choose email to subscribe with

general
  • source: snapd (main)
  • version: 2.76-1
  • maintainer: Michael Hudson-Doyle (DMD)
  • uploaders: Michael Vogt [DMD] – Zygmunt Krynicki [DMD] [DM]
  • arch: all any
  • std-ver: 4.7.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 2.49-1+deb11u2
  • o-o-sec: 2.49-1+deb11u2
  • oldstable: 2.57.6-1+deb12u1
  • old-sec: 2.57.6-1+deb12u1
  • stable: 2.68.3-3+deb13u1
  • stable-sec: 2.68.3-3+deb13u1
  • testing: 2.76-1
  • unstable: 2.76-1
versioned links
  • 2.49-1+deb11u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.57.6-1+deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.68.3-3+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.76-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • golang-github-snapcore-snapd-dev
  • snapd (24 bugs: 0, 21, 3, 0)
action needed
Debci reports failed tests high
  • unstable: fail (log)
    The tests ran in 0:05:21
    Last run: 2026-05-25T00:13:38.000Z
    Previous status: unknown

  • testing: fail (log)
    The tests ran in 0:01:11
    Last run: 2026-07-19T11:36:11.000Z
    Previous status: unknown

  • stable: fail (log)
    The tests ran in 0:02:08
    Last run: 2026-07-24T20:31:54.000Z
    Previous status: unknown

Created: 2026-03-24 Last update: 2026-08-07 07:33
3 security issues in sid high

There are 3 open security issues in sid.

3 important issues:
  • CVE-2024-5300: An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules located in /etc/apparmor.d/abstractions/nss-systemd (inherited via ) inadvertently permit strictly confined snap applications, which lack the privileged account-control interface, to interact directly with the io.systemd.Multiplexer and io.systemd.NameServiceSwitch UNIX domain sockets under /run/systemd/userdb/. On systems where the systemd-userdbd service is installed and operational, the service fails to distinguish between an unconfined root user on the host system and a restricted root user running within a snap application's sandbox (such as a daemon or configuration hook). Because systemd-userdbd returns "complete" user records—including sensitive hashed user passwords from /etc/shadow—when queried by a process running as root, a compromised or malicious strictly confined snap executing code as root can successfully query the Varlink interface to retrieve all system password hashes, bypassing intended snap sandbox restrictions. This issue is mitigated by the fact that systemd-userdbd is not installed by default on standard Ubuntu deployments.
  • CVE-2026-8933: A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations). Due to a flaw in how privilege boundaries or security sandboxes are initialized when the binary runs under limited ambient capabilities, a local, unprivileged attacker can exploit this behavior to bypass intended restrictions and execute arbitrary code. Successful exploitation allows the local user to elevate their privileges to full root authority.
  • CVE-2026-15226: A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution environment compiler (snap-confine). The default seccomp security templates generated by the engine to restrict system calls do not filter or reject process operations capable of creating or manipulating file execution flags with set-user-ID attributes. Consequently, an application running within a strictly confined snap environment can successfully compile or drop binaries and apply setuid properties to them. If a compromised or malicious process inside the snap sandbox executes these generated setuid binaries, it can potentially circumvent architectural sandboxing assumptions, drop intended restriction policies, or execute privileged actions inside the container namespace that should otherwise be strictly blocked. The vulnerability has been resolved by hardening the seccomp template engine to block the execution and creation of setuid executables by sandboxed snap processes.
Created: 2026-07-21 Last update: 2026-08-02 20:32
3 security issues in forky high

There are 3 open security issues in forky.

3 important issues:
  • CVE-2024-5300: An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules located in /etc/apparmor.d/abstractions/nss-systemd (inherited via ) inadvertently permit strictly confined snap applications, which lack the privileged account-control interface, to interact directly with the io.systemd.Multiplexer and io.systemd.NameServiceSwitch UNIX domain sockets under /run/systemd/userdb/. On systems where the systemd-userdbd service is installed and operational, the service fails to distinguish between an unconfined root user on the host system and a restricted root user running within a snap application's sandbox (such as a daemon or configuration hook). Because systemd-userdbd returns "complete" user records—including sensitive hashed user passwords from /etc/shadow—when queried by a process running as root, a compromised or malicious strictly confined snap executing code as root can successfully query the Varlink interface to retrieve all system password hashes, bypassing intended snap sandbox restrictions. This issue is mitigated by the fact that systemd-userdbd is not installed by default on standard Ubuntu deployments.
  • CVE-2026-8933: A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations). Due to a flaw in how privilege boundaries or security sandboxes are initialized when the binary runs under limited ambient capabilities, a local, unprivileged attacker can exploit this behavior to bypass intended restrictions and execute arbitrary code. Successful exploitation allows the local user to elevate their privileges to full root authority.
  • CVE-2026-15226: A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution environment compiler (snap-confine). The default seccomp security templates generated by the engine to restrict system calls do not filter or reject process operations capable of creating or manipulating file execution flags with set-user-ID attributes. Consequently, an application running within a strictly confined snap environment can successfully compile or drop binaries and apply setuid properties to them. If a compromised or malicious process inside the snap sandbox executes these generated setuid binaries, it can potentially circumvent architectural sandboxing assumptions, drop intended restriction policies, or execute privileged actions inside the container namespace that should otherwise be strictly blocked. The vulnerability has been resolved by hardening the seccomp template engine to block the execution and creation of setuid executables by sandboxed snap processes.
Created: 2026-07-21 Last update: 2026-08-02 20:32
9 security issues in bullseye high

There are 9 open security issues in bullseye.

3 important issues:
  • CVE-2024-5300: An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules located in /etc/apparmor.d/abstractions/nss-systemd (inherited via ) inadvertently permit strictly confined snap applications, which lack the privileged account-control interface, to interact directly with the io.systemd.Multiplexer and io.systemd.NameServiceSwitch UNIX domain sockets under /run/systemd/userdb/. On systems where the systemd-userdbd service is installed and operational, the service fails to distinguish between an unconfined root user on the host system and a restricted root user running within a snap application's sandbox (such as a daemon or configuration hook). Because systemd-userdbd returns "complete" user records—including sensitive hashed user passwords from /etc/shadow—when queried by a process running as root, a compromised or malicious strictly confined snap executing code as root can successfully query the Varlink interface to retrieve all system password hashes, bypassing intended snap sandbox restrictions. This issue is mitigated by the fact that systemd-userdbd is not installed by default on standard Ubuntu deployments.
  • CVE-2026-3888: Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.
  • CVE-2026-15226: A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution environment compiler (snap-confine). The default seccomp security templates generated by the engine to restrict system calls do not filter or reject process operations capable of creating or manipulating file execution flags with set-user-ID attributes. Consequently, an application running within a strictly confined snap environment can successfully compile or drop binaries and apply setuid properties to them. If a compromised or malicious process inside the snap sandbox executes these generated setuid binaries, it can potentially circumvent architectural sandboxing assumptions, drop intended restriction policies, or execute privileged actions inside the container namespace that should otherwise be strictly blocked. The vulnerability has been resolved by hardening the seccomp template engine to block the execution and creation of setuid executables by sandboxed snap processes.
6 issues postponed or untriaged:
  • CVE-2021-3155: (needs triaging) snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local attacker to read information that should have been private. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1
  • CVE-2023-1523: (needs triaging) Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause arbitrary commands to be executed outside of the snap sandbox after the snap exits. Graphical terminal emulators like xterm, gnome-terminal and others are not affected - this can only be exploited when snaps are run on a virtual console.
  • CVE-2024-1724: (needs triaging) In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict writes to the $HOME/bin path. In Ubuntu, when this path exists, it is automatically added to the users PATH. An attacker who could convince a user to install a malicious snap which used the 'home' plug could use this vulnerability to install arbitrary scripts into the users PATH which may then be run by the user outside of the expected snap sandbox and hence allow them to escape confinement.
  • CVE-2024-5138: (needs triaging) The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. It was found that snapctl did not properly parse command-line arguments, allowing an unprivileged user to trigger an authorised action on behalf of the snap that would normally require administrator privileges to perform. This could possibly allow an unprivileged user to perform a denial of service or similar.
  • CVE-2024-29068: (needs triaging) In snapd versions prior to 2.62, snapd failed to properly check the file type when extracting a snap. The snap format is a squashfs file-system image and so can contain files that are non-regular files (such as pipes or sockets etc). Various file entries within the snap squashfs image (such as icons etc) are directly read by snapd when it is extracted. An attacker who could convince a user to install a malicious snap which contained non-regular files at these paths could then cause snapd to block indefinitely trying to read from such files and cause a denial of service.
  • CVE-2024-29069: (needs triaging) In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap. The snap format is a squashfs file-system image and so can contain symbolic links and other file types. Various file entries within the snap squashfs image (such as icons and desktop files etc) are directly read by snapd when it is extracted. An attacker who could convince a user to install a malicious snap which contained symbolic links at these paths could then cause snapd to write out the contents of the symbolic link destination into a world-readable directory. This in-turn could allow an unprivileged user to gain access to privileged information.
Created: 2026-03-18 Last update: 2026-08-02 20:32
7 security issues in bookworm high

There are 7 open security issues in bookworm.

2 important issues:
  • CVE-2024-5300: An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules located in /etc/apparmor.d/abstractions/nss-systemd (inherited via ) inadvertently permit strictly confined snap applications, which lack the privileged account-control interface, to interact directly with the io.systemd.Multiplexer and io.systemd.NameServiceSwitch UNIX domain sockets under /run/systemd/userdb/. On systems where the systemd-userdbd service is installed and operational, the service fails to distinguish between an unconfined root user on the host system and a restricted root user running within a snap application's sandbox (such as a daemon or configuration hook). Because systemd-userdbd returns "complete" user records—including sensitive hashed user passwords from /etc/shadow—when queried by a process running as root, a compromised or malicious strictly confined snap executing code as root can successfully query the Varlink interface to retrieve all system password hashes, bypassing intended snap sandbox restrictions. This issue is mitigated by the fact that systemd-userdbd is not installed by default on standard Ubuntu deployments.
  • CVE-2026-15226: A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution environment compiler (snap-confine). The default seccomp security templates generated by the engine to restrict system calls do not filter or reject process operations capable of creating or manipulating file execution flags with set-user-ID attributes. Consequently, an application running within a strictly confined snap environment can successfully compile or drop binaries and apply setuid properties to them. If a compromised or malicious process inside the snap sandbox executes these generated setuid binaries, it can potentially circumvent architectural sandboxing assumptions, drop intended restriction policies, or execute privileged actions inside the container namespace that should otherwise be strictly blocked. The vulnerability has been resolved by hardening the seccomp template engine to block the execution and creation of setuid executables by sandboxed snap processes.
5 issues postponed or untriaged:
  • CVE-2023-1523: (needs triaging) Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause arbitrary commands to be executed outside of the snap sandbox after the snap exits. Graphical terminal emulators like xterm, gnome-terminal and others are not affected - this can only be exploited when snaps are run on a virtual console.
  • CVE-2024-1724: (needs triaging) In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict writes to the $HOME/bin path. In Ubuntu, when this path exists, it is automatically added to the users PATH. An attacker who could convince a user to install a malicious snap which used the 'home' plug could use this vulnerability to install arbitrary scripts into the users PATH which may then be run by the user outside of the expected snap sandbox and hence allow them to escape confinement.
  • CVE-2024-5138: (needs triaging) The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. It was found that snapctl did not properly parse command-line arguments, allowing an unprivileged user to trigger an authorised action on behalf of the snap that would normally require administrator privileges to perform. This could possibly allow an unprivileged user to perform a denial of service or similar.
  • CVE-2024-29068: (needs triaging) In snapd versions prior to 2.62, snapd failed to properly check the file type when extracting a snap. The snap format is a squashfs file-system image and so can contain files that are non-regular files (such as pipes or sockets etc). Various file entries within the snap squashfs image (such as icons etc) are directly read by snapd when it is extracted. An attacker who could convince a user to install a malicious snap which contained non-regular files at these paths could then cause snapd to block indefinitely trying to read from such files and cause a denial of service.
  • CVE-2024-29069: (needs triaging) In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap. The snap format is a squashfs file-system image and so can contain symbolic links and other file types. Various file entries within the snap squashfs image (such as icons and desktop files etc) are directly read by snapd when it is extracted. An attacker who could convince a user to install a malicious snap which contained symbolic links at these paths could then cause snapd to write out the contents of the symbolic link destination into a world-readable directory. This in-turn could allow an unprivileged user to gain access to privileged information.
Created: 2023-06-10 Last update: 2026-08-02 20:32
1 bug tagged patch in the BTS normal
The BTS contains patches fixing 1 bug, consider including or untagging them.
Created: 2026-06-02 Last update: 2026-08-07 07:30
Fails to build during reproducibility testing normal
A package building reproducibly enables third parties to verify that the source matches the distributed binaries. It has been identified that this source package produced different results, failed to build or had other issues in a test environment. Please read about how to improve the situation!
Created: 2025-10-15 Last update: 2026-08-07 05:20
3 low-priority security issues in trixie low

There are 3 open security issues in trixie.

2 issues left for the package maintainer to handle:
  • CVE-2024-5300: (needs triaging) An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules located in /etc/apparmor.d/abstractions/nss-systemd (inherited via ) inadvertently permit strictly confined snap applications, which lack the privileged account-control interface, to interact directly with the io.systemd.Multiplexer and io.systemd.NameServiceSwitch UNIX domain sockets under /run/systemd/userdb/. On systems where the systemd-userdbd service is installed and operational, the service fails to distinguish between an unconfined root user on the host system and a restricted root user running within a snap application's sandbox (such as a daemon or configuration hook). Because systemd-userdbd returns "complete" user records—including sensitive hashed user passwords from /etc/shadow—when queried by a process running as root, a compromised or malicious strictly confined snap executing code as root can successfully query the Varlink interface to retrieve all system password hashes, bypassing intended snap sandbox restrictions. This issue is mitigated by the fact that systemd-userdbd is not installed by default on standard Ubuntu deployments.
  • CVE-2026-15226: (needs triaging) A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution environment compiler (snap-confine). The default seccomp security templates generated by the engine to restrict system calls do not filter or reject process operations capable of creating or manipulating file execution flags with set-user-ID attributes. Consequently, an application running within a strictly confined snap environment can successfully compile or drop binaries and apply setuid properties to them. If a compromised or malicious process inside the snap sandbox executes these generated setuid binaries, it can potentially circumvent architectural sandboxing assumptions, drop intended restriction policies, or execute privileged actions inside the container namespace that should otherwise be strictly blocked. The vulnerability has been resolved by hardening the seccomp template engine to block the execution and creation of setuid executables by sandboxed snap processes.

You can find information about how to handle these issues in the security team's documentation.

1 ignored issue:
  • CVE-2026-8933: A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations). Due to a flaw in how privilege boundaries or security sandboxes are initialized when the binary runs under limited ambient capabilities, a local, unprivileged attacker can exploit this behavior to bypass intended restrictions and execute arbitrary code. Successful exploitation allows the local user to elevate their privileges to full root authority.
Created: 2026-07-21 Last update: 2026-08-02 20:32
debian/patches: 4 patches to forward upstream low

Among the 4 debian patches available in version 2.76-1 of the package, we noticed the following issues:

  • 4 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-07-02 10:02
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.7.2).
Created: 2025-12-23 Last update: 2026-07-01 21:18
news
[rss feed]
  • [2026-07-07] snapd 2.76-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-01] Accepted snapd 2.76-1 (source) into unstable (Zygmunt Krynicki) (signed by: Zygmunt Bazyli Krynicki)
  • [2026-05-30] snapd 2.75.2-2 MIGRATED to testing (Debian testing watch)
  • [2026-05-25] Accepted snapd 2.75.2-2 (source) into unstable (Zygmunt Krynicki) (signed by: Zygmunt Bazyli Krynicki)
  • [2026-04-23] snapd 2.75.2-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-17] Accepted snapd 2.75.2-1 (source) into unstable (Zygmunt Krynicki) (signed by: Zygmunt Bazyli Krynicki)
  • [2026-03-27] Accepted snapd 2.57.6-1+deb12u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2026-03-22] Accepted snapd 2.68.3-3+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2026-03-19] Accepted snapd 2.57.6-1+deb12u1 (source) into oldstable-security (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2026-03-19] Accepted snapd 2.68.3-3+deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2026-03-18] snapd 2.74.1-1 MIGRATED to testing (Debian testing watch)
  • [2026-03-13] Accepted snapd 2.74.1-1 (source) into unstable (Zygmunt Krynicki) (signed by: Zygmunt Bazyli Krynicki)
  • [2026-03-13] Accepted snapd 2.73-4 (source) into unstable (Zygmunt Krynicki) (signed by: Zygmunt Bazyli Krynicki)
  • [2026-02-27] Accepted snapd 2.73-3 (source) into unstable (Zygmunt Krynicki) (signed by: Zygmunt Bazyli Krynicki)
  • [2026-01-26] Accepted snapd 2.72-1 (source) into unstable (Zygmunt Krynicki) (signed by: Zygmunt Bazyli Krynicki)
  • [2025-10-14] snapd 2.71-3 MIGRATED to testing (Debian testing watch)
  • [2025-08-21] Accepted snapd 2.71-3 (source) into unstable (Zygmunt Krynicki) (signed by: Zygmunt Bazyli Krynicki)
  • [2025-08-21] Accepted snapd 2.71-2 (source) into unstable (Zygmunt Krynicki) (signed by: Zygmunt Bazyli Krynicki)
  • [2025-08-21] Accepted snapd 2.71-1 (source) into unstable (Zygmunt Krynicki) (signed by: Zygmunt Bazyli Krynicki)
  • [2025-07-20] snapd 2.68.3-3 MIGRATED to testing (Debian testing watch)
  • [2025-07-15] Accepted snapd 2.68.3-3 (source) into unstable (Zygmunt Krynicki) (signed by: Zygmunt Bazyli Krynicki)
  • [2025-03-31] snapd 2.68.3-2 MIGRATED to testing (Debian testing watch)
  • [2025-03-25] Accepted snapd 2.68.3-2 (source) into unstable (Zygmunt Krynicki) (signed by: Zygmunt Bazyli Krynicki)
  • [2025-02-02] snapd 2.67-1 MIGRATED to testing (Debian testing watch)
  • [2025-01-28] Accepted snapd 2.67-1 (source) into unstable (Zygmunt Krynicki) (signed by: Zygmunt Bazyli Krynicki)
  • [2025-01-27] snapd 2.66.1-2 MIGRATED to testing (Debian testing watch)
  • [2025-01-18] Accepted snapd 2.66.1-2 (source) into unstable (Zygmunt Krynicki) (signed by: Zygmunt Bazyli Krynicki)
  • [2024-11-28] Accepted snapd 2.66.1-1 (source) into unstable (Zygmunt Krynicki) (signed by: Zygmunt Bazyli Krynicki)
  • [2024-09-24] snapd 2.65.3-1 MIGRATED to testing (Debian testing watch)
  • [2024-09-19] Accepted snapd 2.65.3-1 (source) into unstable (Zygmunt Krynicki) (signed by: Zygmunt Bazyli Krynicki)
  • 1
  • 2
bugs [bug history graph]
  • all: 38
  • RC: 1
  • I&N: 31
  • M&W: 6
  • F&P: 0
  • patch: 1
  • NC: 1
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • screenshots
  • l10n (-, 26)
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.76.3+ubuntu26.10

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing