VYPR
Critical severity9.3NVD Advisory· Published Jun 21, 2024· Updated Jun 17, 2026

CVE-2020-27352

CVE-2020-27352

Description

When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd will move processes from the containers created and managed by these snaps into the cgroup of the main daemon within the snap itself when reloading system units. This may grant additional privileges to a container within the snap that were not originally intended.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • Canonical Ltd./snapdv5
    Range: 0
  • cpe:2.3:a:canonical:snapd:*:*:*:*:*:*:*:*
    Range: <2.48.3
  • cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*+ 3 more
    • cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:20.10:*:*:*:*:*:*:*
  • snapd/snapdllm-fuzzy

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.