High severity7.8NVD Advisory· Published Jan 8, 2024· Updated Jun 17, 2026
CVE-2022-3328
CVE-2022-3328
Description
Race condition in snap-confine's must_mkdir_and_open_with_perms()
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/snapcore/snapdGo | < 2.57.6 | 2.57.6 |
Affected products
8cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*+ 4 more
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:esm:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:22.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:22.10:*:*:*:-:*:*:*
- Canonical Ltd./snapdv5Range: 0
Patches
Vulnerability mechanics
References
7- cve.mitre.org/cgi-bin/cvename.cginvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-cjqf-877p-7m3fghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-3328ghsaADVISORY
- ubuntu.com/security/notices/USN-5753-1nvdVendor AdvisoryWEB
- github.com/snapcore/snapd/commit/21ebc51f00b8a1417888faa2e83a372fd29d0f5eghsaWEB
- github.com/snapcore/snapd/commit/6226cdc57052f4b7057d92f2e549aa169e35cd2dghsaWEB
- github.com/snapcore/snapd/pull/12380ghsaWEB
News mentions
1- Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop InstallsThe Hacker News · Jul 22, 2026