A vulnerability in Canonical snapd prior to version 2.37.1 allowed incorrect validation of socket ownership, enabling local attackers to execute arbitrary commands as root. The flaw is due to improper checking of the owner of the UNIX socket used by snapd, which could be exploited to gain root privileges.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository contains two Python scripts, dirty_sockv1.py and dirty_sockv2.py, which are local privilege escalation exploits targeting a vulnerability in the snapd service on Linux systems (notably Ubuntu). The exploit leverages insecure parsing of UNIX socket peer credentials by snapd, allowing a local attacker to impersonate root (UID=0) when communicating with the snapd API via a specially crafted UNIX socket file. - dirty_sockv1.py exploits the /v2/create-user API endpoint to create a new local user with sudo privileges, using information from an Ubuntu SSO account. It requires outbound Internet access and a running SSH service on localhost. The script automates the process, including SSH access to the new account. - dirty_sockv2.py exploits the /v2/snaps API endpoint to sideload a malicious snap package (embedded as a base64 string in the script) with an install hook that creates a new user 'dirty_sock' with password 'dirty_sock' and sudo privileges. This version does not require Internet or SSH and is more suitable for restricted environments. Both scripts require local access to the target system and a vulnerable version of snapd (<2.37.1). The main attack vector is local, exploiting the snapd UNIX socket. The repository is well-documented, with a README explaining usage, requirements, and troubleshooting. No external network endpoints are targeted; all communication is local to the system.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.