CVE-2019-7304: Canonical Snapd
Critical severity, CVSS 9.8. EPSS: 60.8% chance of exploitation in the next 30 days.
Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root. This issue affects: Canonical snapd versions prior to 2.37.1.
Affected products
- Canonical Snapd: before 2.37.1 (fixed in 2.37.1)
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 18.10 only
Published 2019-04-23. Last modified 2026-06-17.