High severity7.5OSV Advisory· Published Apr 24, 2019· Updated Jun 17, 2026
CVE-2019-11502
CVE-2019-11502
Description
snap-confine in snapd before 2.38 incorrectly set the ownership of a snap application to the uid and gid of the first calling user. Consequently, that user had unintended access to a private /tmp directory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: <2.38
Patches
Vulnerability mechanics
References
3- github.com/snapcore/snapd/commit/bdbfeebef03245176ae0dc323392bb0522a339b1nvdPatchThird Party Advisory
- www.openwall.com/lists/oss-security/2019/04/18/4nvdExploitMailing ListPatchThird Party Advisory
- www.openwall.com/lists/oss-security/2019/04/25/7nvdThird Party Advisory
News mentions
0No linked articles in our index yet.