CVE-2024-5138
Estado: AnalizadaAlta (8.1)—
The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. It was found that snapctl did not properly parse command-line arguments, allowing an unprivileged user to trigger an authorised action on behalf of the snap that would normally require administrator privileges to perform. This could possibly allow an unprivileged user to perform a denial of service or similar.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
- Puntuación base: 8.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.83%
- Percentil entre todas las CVEs puntuadas: 56
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-20
Referencias
- https://bugs.launchpad.net/snapd/+bug/2065077
- https://github.com/snapcore/snapd/commit/68ee9c6aa916ab87dbfd9a26030690f2cabf1e14
- https://github.com/snapcore/snapd/security/advisories/GHSA-p9v8-q5m4-pf46
- https://www.cve.org/CVERecord?id=CVE-2024-5138
- https://bugs.launchpad.net/snapd/+bug/2065077
- https://github.com/snapcore/snapd/commit/68ee9c6aa916ab87dbfd9a26030690f2cabf1e14
- https://github.com/snapcore/snapd/security/advisories/GHSA-p9v8-q5m4-pf46
- https://www.cve.org/CVERecord?id=CVE-2024-5138
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-5138",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-5138",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-08-07T19:03:04.672013Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 5.2,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security@ubuntu.com",
"affectedData": [
{
"repo": "https://github.com/snapcore/snapd",
"vendor": "Canonical Ltd.",
"product": "snapd",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "68ee9c6aa916ab87dbfd9a26030690f2cabf1e14",
"versionType": "custom"
}
],
"platforms": [
"Linux"
],
"packageName": "snapd"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:canonical:snapd:*:*:*:*:*:*:*:*"
],
"vendor": "canonical",
"product": "snapd",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "68ee9c6aa916ab87dbfd9a26030690f2cabf1e14",
"versionType": "git"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-05-31T21:15:09.930",
"references": [
{
"url": "https://bugs.launchpad.net/snapd/+bug/2065077",
"tags": [
"Exploit",
"Issue Tracking",
"Patch"
],
"source": "security@ubuntu.com"
},
{
"url": "https://github.com/snapcore/snapd/commit/68ee9c6aa916ab87dbfd9a26030690f2cabf1e14",
"tags": [
"Patch"
],
"source": "security@ubuntu.com"
},
{
"url": "https://github.com/snapcore/snapd/security/advisories/GHSA-p9v8-q5m4-pf46",
"tags": [
"Vendor Advisory"
],
"source": "security@ubuntu.com"
},
{
"url": "https://www.cve.org/CVERecord?id=CVE-2024-5138",
"tags": [
"Third Party Advisory"
],
"source": "security@ubuntu.com"
},
{
"url": "https://bugs.launchpad.net/snapd/+bug/2065077",
"tags": [
"Exploit",
"Issue Tracking",
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/snapcore/snapd/commit/68ee9c6aa916ab87dbfd9a26030690f2cabf1e14",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/snapcore/snapd/security/advisories/GHSA-p9v8-q5m4-pf46",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.cve.org/CVERecord?id=CVE-2024-5138",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. It was found that snapctl did not properly parse command-line arguments, allowing an unprivileged user to trigger an authorised action on behalf of the snap that would normally require administrator privileges to perform. This could possibly allow an unprivileged user to perform a denial of service or similar."
},
{
"lang": "es",
"value": "El componente snapctl dentro de snapd permite que un complemento confinado interactúe con el daemon snapd para realizar ciertas acciones privilegiadas en nombre del complemento. Se descubrió que snapctl no analizaba adecuadamente los argumentos de la línea de comandos, lo que permitía a un usuario sin privilegios activar una acción autorizada en nombre del complemento que normalmente requeriría privilegios de administrador para realizarse. Esto posiblemente podría permitir que un usuario sin privilegios realice una denegación de servicio o algo similar."
}
],
"lastModified": "2026-06-17T08:15:16.680",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:canonical:snapd:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3929DBD2-3EFE-418A-AEB8-3D4DEF3E694F",
"versionEndExcluding": "2.63.1",
"versionStartIncluding": "2.51.6"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@ubuntu.com"
}