Ubuntu snap-confine patch release (CVE-2026-8933)
Security Patch Release
Updated: 22.07.2026 13:50
· First: 22.07.2026 13:50
· 📰 2 src / 2 articles
· H score: 34
Canonical released snapd updates through the Ubuntu Security Team to fix CVE-2026-8933, a local privilege escalation in snap-confine that can let an unprivileged user obtain root access on default Ubuntu Desktop 24.04, 25.10, and 26.04 installations. Qualys Threat Research Unit disclosed the flaw on July 21 and described a race condition during sandbox initialization that can be chained to write malicious rules under /run/udev/rules.d/ and trigger systemd-udevd as root. Administrators were urged to verify the installed snapd version and apply the latest package updates immediately to reduce the risk of local root compromise on exposed desktop and endpoint systems.