VYPR
High severity8.2NVD Advisory· Published Feb 17, 2022· Updated Jun 17, 2026

CVE-2021-4120

CVE-2021-4120

Description

snapd 2.54.2 fails to perform sufficient validation of snap content interface and layout paths, resulting in the ability for snaps to inject arbitrary AppArmor policy rules via malformed content interface and layout declarations and hence escape strict snap confinement. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

9
  • Canonical/Snapd2 versions
    cpe:2.3:a:canonical:snapd:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:canonical:snapd:*:*:*:*:*:*:*:*range: <=2.54.2
    • (no CPE)range: 2.54.2
  • cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*+ 2 more
    • cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:21.10:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
  • Ubuntu/snapdllm-fuzzy
    Range: 2.54.2
  • Canonical Ltd./snapdv5
    Range: unspecified

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.