CVE-2019-7304
HIGH 10.0EPSS 60.8%
Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root. This issue affects: Canonical snapd versions prior to 2.37.1.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.0
- 8.8 HIGH
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H - CVSS v2.0
- 10.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 60.81% chance of exploitation in the next 30 days, 99th percentile
- Published
- 2019-04-23
- Updated
- 2024-09-16
Proof-of-concept exploits (9)
- Dhayalanb/Snapd-V21★ · 2019-06-05
- SecuritySi/CVE-2019-7304_DirtySock6★ · 2019-02-14
- VieVaWaldi/DirtySock0★ · 2019-07-03
- WalterEhren/DirtySock0★ · 2019-07-03
- WalterEren/DirtySock0★ · 2019-07-03
- coby-nguyen/Document-Linux-Privilege-Escalation0★ · 2025-06-25
- elvi7major/snap_priv_esc1★ · 2021-03-28
- f4T1H21/dirty_sock1★ · 2021-07-28
- initstring/dirty_sock681★ · 2019-05-09