Low
CVSS: 1.9
It was discovered that process_crash() in data/apport in Canonical's Apport crash reporting tool may create crash files with incorrect group ownership, possibly exposing crash information beyond expected or intended groups.
Medium
CVSS: 4.7
Race condition in Canonical apport up to and including 2.32.0 allows a local attacker to leak sensitive information via PID-reuse by leveraging namespaces.
When handling a crash, the function `_check_global_pid_and_forward`, which detec…
Low
CVSS: 3.1
gdbus setgid privilege escalation
High
CVSS: 7.5
Users can consume unlimited disk space in /var/crash