VYPR
High severity7.8NVD Advisory· Published Jan 8, 2024· Updated Jun 17, 2026

CVE-2022-3328

CVE-2022-3328

Description

Race condition in snap-confine's must_mkdir_and_open_with_perms()

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/snapcore/snapdGo
< 2.57.62.57.6

Affected products

8
  • cpe:2.3:a:canonical:snapd:*:*:*:*:*:*:*:*
    Range: <2.61.1
  • cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*+ 4 more
    • cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:esm:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:22.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:22.10:*:*:*:-:*:*:*
  • ghsa-coords
    Range: < 2.57.6
  • Canonical Ltd./snapdv5
    Range: 0

Patches

Vulnerability mechanics

References

7

News mentions

1