CVE-2026-3888 is a local privilege-escalation vulnerability in snapd’s snap-confine temporary-directory handling on Ubuntu Linux. A privileged snap sandbox setup relies on a Snap-private directory beneath the world-writable /tmp hierarchy being root-owned. systemd-tmpfiles-clean.service can recursively remove that directory after its configured inactivity period without accounting for active namespace references. A low-privileged local user can then recreate the deleted directory under attacker ownership. During a later snap-confine sandbox initialization, snap-confine can use or bind-mount attacker-controlled content as root, enabling a privilege-escalation chain. The issue is a time-of-check/time-of-use race involving unsafe temporary-directory lifecycle and ownership assumptions. Default Ubuntu Desktop installations from 24.04 onward are affected; the CVE record also identifies Ubuntu 16.04 LTS through 24.04 LTS where the relevant systemd-tmpfiles cleanup configuration is present.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
6 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This is a small standalone local privilege escalation repository, not tied to a common exploit framework. It contains 3 files: a README, the main exploit source (exploit_fixed.c), and a minimal payload source (librootshell_suid.c). The repository targets CVE-2026-3888, described as a snap-confine/systemd-tmpfiles SUID LPE on Linux. The main exploit is a multi-phase local attack against snap-confine. From the visible code and README, it builds a crafted .snap directory hierarchy, mirrors Firefox snap revision/data-dir paths, and copies the core22 library directory into an attacker-controlled exchange directory. It then launches /usr/lib/snapd/snap-confine with controlled environment variables, races namespace/tmpfiles behavior, and attempts to poison a library path inside the sandbox. The README notes two reliability fixes: a fallback to use the forked child PID directly via /proc/<child>/root when race_pid.txt is unavailable, and a fallback to directly modify .snap/usr/lib/x86_64-linux-gnu/ld-linux from /tmp when no live process remains in the poisoned namespace. The exploit’s purpose is to replace or hijack the dynamic loader path used in the privileged context so that attacker code runs as root. The supplied payload is a tiny static binary/source that immediately calls setreuid(0,0), setregid(0,0), and execve("/tmp/sh"). In addition, the main exploit embeds an escape script that copies /bin/bash to /var/snap/firefox/common/bash and marks it SUID (04755), providing a persistent root-capable shell path. Overall capability: reliable local root escalation on vulnerable Linux systems with snapd/snap-confine and expected snap filesystem layout. No network communication is present; the attack vector is purely local and heavily dependent on filesystem paths, namespace manipulation, and race timing.
This repository is a compact local privilege-escalation exploit for CVE-2026-3888 targeting snap-confine in a Firefox snap environment on Linux. It contains two C source files and a markdown walkthrough. The main exploit logic is in firefox_2404_final.c, which prepares a fake .snap directory tree in the current working directory, mirrors the host library directory /usr/lib/x86_64-linux-gnu into .snap/usr/lib/x86_64-linux-gnu.exchange, and then launches /usr/lib/snapd/snap-confine with SNAPD_DEBUG enabled. The code reads snap-confine stderr over a UNIX socketpair and waits for a specific debug line referencing /tmp/.snap/usr/lib/x86_64-linux-gnu. When that trigger appears, it atomically swaps the expected library directory with the attacker-controlled exchange directory using renameat2(RENAME_EXCHANGE), with a rename fallback if needed. This is the core race capability. The second source file, librootshell.c, is a minimal payload intended to replace ld-linux-x86-64.so.2. It uses raw syscalls to set real/effective UID and GID to 0 and then execve /tmp/sh. In the documented workflow, the attacker plants a static shell binary at /tmp/sh inside the poisoned namespace, overwrites the namespace-visible ld-linux-x86-64.so.2 with the compiled librootshell payload, and then re-executes snap-confine so the SUID-root binary loads the malicious dynamic linker and spawns a root shell. Repository structure is straightforward: GUIDE.md provides a full HTB-style operational procedure with compilation commands, three-terminal execution steps, troubleshooting notes, and post-exploitation instructions; firefox_2404_final.c is the race helper and main entry point; librootshell.c is the privilege-escalation payload. This is not a scanner or detector: it is a real exploit chain for local root escalation, with a hardcoded but functional payload and explicit post-exploitation steps to create a SUID bash under /var/snap/firefox/common/. The code is operational rather than framework-based, and the exploit is clearly intended for a specific vulnerable snapd/Firefox-snap setup on x86_64 Linux.
This repository is a small, self-contained local privilege escalation exploit and write-up for CVE-2026-3888 affecting Ubuntu Desktop 24.04-era snapd/snap-confine behavior. The repo contains 8 files total: 5 markdown analysis documents, 1 README, and 2 C source files. The markdown files provide a detailed walkthrough of the vulnerability, the TOCTOU condition, the AF_UNIX backpressure technique, exploitation steps, and mitigations. The actual exploit logic lives in src/firefox_2404.c and src/librootshell.c. The main exploit capability is local root escalation by abusing the interaction between snap-confine and systemd-tmpfiles. The exploit relies on /tmp/.snap being deleted by systemd-tmpfiles and then recreated under attacker control. The helper program firefox_2404.c prepares an attacker-owned .snap tree, copies legitimate libraries from /snap/core22/current/usr/lib/x86_64-linux-gnu into an exchange directory, launches /usr/lib/snapd/snap-confine with SNAPD_DEBUG=1, and redirects stderr through a deliberately tiny AF_UNIX socketpair. By reading one byte at a time, the parent process applies backpressure and effectively single-steps snap-confine's debug output. When the trigger string dir:"/tmp/.snap/usr/lib/x86_64-linux-gnu" appears, the helper atomically swaps .snap/usr/lib/x86_64-linux-gnu with .snap/usr/lib/x86_64-linux-gnu.exchange using renameat2(RENAME_EXCHANGE). This causes snap-confine to bind-mount attacker-controlled library content as root into the namespace. The second code file, librootshell.c, is the payload. It is a minimal fake dynamic loader intended to replace ld-linux-x86-64.so.2 inside the poisoned namespace. It uses raw x86_64 syscalls only, sets real/effective UID and GID to 0, and execs /tmp/sh. The documented exploitation flow then places a static busybox shell at /tmp/sh, overwrites /usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2 in the namespace with the compiled payload, and executes the SUID snap-confine binary so the kernel loads the malicious interpreter as root. The repository documentation further describes escaping the firefox AppArmor confinement by writing a SUID bash to /var/snap/firefox/common/. Overall, this is not a scanner or detector; it is an operational exploit with a concrete payload and a reliable race-winning mechanism. It targets a local Linux environment rather than a network service, and the most important fingerprintable artifacts are filesystem paths and process-namespace paths rather than remote endpoints.
This repository contains a real local privilege escalation exploit for CVE-2026-3888 targeting Ubuntu systems that use snap-confine together with systemd-tmpfiles. The repo is small and purpose-built: one README, two main exploit programs in C, and two payload source files. It is not part of a larger exploit framework. Structure: - README.md documents the vulnerability, build steps, usage, requirements, and lab setup. - exploit_suid.c implements the Ubuntu 24.04-style SUID-root snap-confine variant. - exploit_caps.c implements the Ubuntu 25.10-style capabilities-based snap-confine variant. - librootshell_suid.c is a minimal raw-syscall ELF payload intended to replace ld-linux-x86-64.so.2. - librootshell_caps.c is an LD_PRELOAD-style shared library payload using a constructor. Core capability: Both exploit variants aim to win a TOCTOU race around cleanup of a stale /tmp/.snap tree and snap-confine’s bind-mount/mimic behavior. The exploit prepares an attacker-controlled replacement directory tree, throttles snap-confine execution using an AF_UNIX socketpair on stderr to improve race reliability, then swaps in malicious content that will be consumed by a privileged execution path. SUID variant behavior: The SUID exploit targets systems where /usr/lib/snapd/snap-confine is SUID-root. It mirrors /snap/core22/current/usr/lib/x86_64-linux-gnu into an attacker-controlled .snap exchange directory, then poisons the dynamic linker path so that privileged snap-confine execution loads attacker code. The payload directly performs setreuid/setregid and execve('/tmp/sh'). The exploit then drops a SUID bash to /var/snap/firefox/common/bash for a persistent root shell outside the sandbox. Capabilities variant behavior: The capabilities exploit targets systems where snap-confine uses Linux capabilities rather than SUID. It mirrors /snap/core22/current/var/lib, manipulates a user-fstab path, and relies on ld.so.preload-style hijacking so that a SUID su binary reachable under the hostfs path loads the attacker’s shared object. The constructor payload escalates to uid/gid 0 and execs /tmp/sh. It similarly installs a SUID bash at /var/snap/snap-store/common/bash. Notable implementation details: - Both main exploit files are statically linked C programs intended to run inside the snap sandbox. - They create and populate attacker-controlled directory trees under .snap. - They enumerate installed snap revisions under /snap/firefox or /snap/snap-store to mimic expected layout. - They use local filesystem paths and environment shaping rather than network communication. - No external C2, URLs, or remote IPs are present; this is strictly a local exploit. Overall assessment: This is an operational local root exploit repository, not a detector or proof-of-concept only. It includes working payloads and post-exploitation steps to obtain an interactive root shell and a reusable SUID bash. The attack vector is entirely local and depends on vulnerable snapd/snap-confine behavior, tmpfiles cleanup timing, and specific snap layout conditions on Ubuntu.
This repository is a small local privilege-escalation style proof of concept consisting of three files: a README, a Python race orchestrator, and a C shared-library payload. The README instructs the user to compile `payload.c` into `/tmp/libpayload.so` using `gcc -shared -fPIC`. The main exploit logic is in `cve-2026-3888.py`, which continuously launches the `hello-world` executable in multiple threads while separate racing threads repeatedly create and remove a symlink at `/tmp/snap.hello-world` pointing to `/tmp/libpayload.so`. The apparent goal is to exploit a race/symlink vulnerability so that the target process loads the attacker-controlled shared object. The payload in `payload.c` is a constructor-based shared library: as soon as it is loaded, it executes shell commands via `system()`, writing a marker string and the output of `id` to `/tmp/pwn.txt`. This demonstrates arbitrary command execution in the context of the vulnerable process. The Python script, however, waits for `/tmp/root_sh` as its success condition, and that file is never created by the included payload, indicating the PoC is somewhat inconsistent or incomplete. Despite that mismatch, the repository clearly implements a real local race-condition/symlink exploit attempt rather than a detector. There are no network endpoints; all observable targets are local filesystem paths and the local `hello-world` command.
This repository is a small standalone proof-of-concept exploit for CVE-2026-3888, described as a local privilege escalation issue in snapd on Ubuntu. The repository contains four files: an MIT license, a README in Spanish explaining the vulnerability and usage, a short references file, and the main Python exploit script cve_2026_3888_poc.py. There is no external exploit framework involved. The exploit script is structured as a simple end-to-end workflow: check_vulnerability() verifies the host looks like Ubuntu, confirms snapd is installed by reading /etc/os-release and invoking snap version, and checks whether /tmp/.snap currently exists. create_malicious_library() writes embedded C code to /tmp/payload.c and compiles it with gcc into a shared object named libpthread.so.0 under /tmp/.snap. The embedded payload uses a constructor function so that when the library is loaded it writes /tmp/pwn.txt and appends the output of id as proof of privileged execution. trigger_exploit() then attempts to run a snap application, preferring hello-world and otherwise selecting the first installed snap from snap list, using snap run <target> to trigger the vulnerable path. cleanup() removes /tmp/.snap and /tmp/pwn.txt. The script also supports a --cleanup mode. Main exploit capability: local privilege escalation from an unprivileged user to root by abusing a race/cleanup condition around snap’s private temporary directory and a privileged snap execution path. The exploit is operational rather than a mere detector because it builds and deploys a real payload and attempts to trigger it automatically. It does not include remote networking, C2, persistence, or data exfiltration. Its observable artifacts are local filesystem paths and local command invocations, especially /tmp/.snap, /tmp/.snap/libpthread.so.0, /tmp/payload.c, /tmp/pwn.txt, and snap/gcc command execution. One caveat: the provided script content appears truncated near the end of main(), but enough code is present to determine the exploit’s purpose, payload, attack vector, and operational flow.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
159 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-severity local privilege escalation vulnerability in Ubuntu involving snap-confine and systemd-tmpfiles, where attackers can exploit a time-based cleanup window to gain root access and fully compromise the host.
Another vulnerability in the snap-confine component mentioned for historical context.
A related snap-confine vulnerability from 2026 mentioned for comparison only.
The content references CVE-2026-3888 in the context of a Metasploit module addition, indicating it is a specific vulnerability being operationalized for exploitation tooling, but no technical details are provided.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.