CVE Feed

    Dashboard / CVE / CVE-2020-27352

    CVE-2020-27352

    When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd will move processes from the containers created and managed by these snaps into the cgroup of the main daemon within the snap itself when reloading system units. This may grant additional privileges to a container within the snap that were not originally intended.

    Published:Jun 21, 2024
    Last Modified:Aug 26, 2025
    EPS:Jun 21, 2024
    EPSS Score:0.00112
    CVSS Score:9.3

    Affected Products

    Vendor
    Canonical
    Product
    Snapd
    Vendor
    Canonical
    Product
    Ubuntu Linux

    Common Weakness Enumeration

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High