snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local attacker to read information that should have been private. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1
{
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "2.54.3+16.04~esm2",
"binary_name": "golang-github-snapcore-snapd-dev"
},
{
"binary_version": "2.54.3+16.04~esm2",
"binary_name": "golang-github-ubuntu-core-snappy-dev"
},
{
"binary_version": "2.54.3+16.04~esm2",
"binary_name": "snap-confine"
},
{
"binary_version": "2.54.3+16.04~esm2",
"binary_name": "snapd"
},
{
"binary_version": "2.54.3+16.04~esm2",
"binary_name": "snapd-xdg-open"
},
{
"binary_version": "2.54.3+16.04~esm2",
"binary_name": "ubuntu-core-launcher"
},
{
"binary_version": "2.54.3+16.04~esm2",
"binary_name": "ubuntu-core-snapd-units"
},
{
"binary_version": "2.54.3+16.04~esm2",
"binary_name": "ubuntu-snappy"
},
{
"binary_version": "2.54.3+16.04~esm2",
"binary_name": "ubuntu-snappy-cli"
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "2.54.3+18.04",
"binary_name": "golang-github-snapcore-snapd-dev"
},
{
"binary_version": "2.54.3+18.04",
"binary_name": "golang-github-ubuntu-core-snappy-dev"
},
{
"binary_version": "2.54.3+18.04",
"binary_name": "snap-confine"
},
{
"binary_version": "2.54.3+18.04",
"binary_name": "snapd"
},
{
"binary_version": "2.54.3+18.04",
"binary_name": "snapd-xdg-open"
},
{
"binary_version": "2.54.3+18.04",
"binary_name": "ubuntu-core-launcher"
},
{
"binary_version": "2.54.3+18.04",
"binary_name": "ubuntu-core-snapd-units"
},
{
"binary_version": "2.54.3+18.04",
"binary_name": "ubuntu-snappy"
},
{
"binary_version": "2.54.3+18.04",
"binary_name": "ubuntu-snappy-cli"
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "2.54.3+20.04.1",
"binary_name": "golang-github-snapcore-snapd-dev"
},
{
"binary_version": "2.54.3+20.04.1",
"binary_name": "golang-github-ubuntu-core-snappy-dev"
},
{
"binary_version": "2.54.3+20.04.1",
"binary_name": "snap-confine"
},
{
"binary_version": "2.54.3+20.04.1",
"binary_name": "snapd"
},
{
"binary_version": "2.54.3+20.04.1",
"binary_name": "snapd-xdg-open"
},
{
"binary_version": "2.54.3+20.04.1",
"binary_name": "ubuntu-core-launcher"
},
{
"binary_version": "2.54.3+20.04.1",
"binary_name": "ubuntu-core-snapd-units"
},
{
"binary_version": "2.54.3+20.04.1",
"binary_name": "ubuntu-snappy"
},
{
"binary_version": "2.54.3+20.04.1",
"binary_name": "ubuntu-snappy-cli"
}
]
}