Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root. This issue affects: Canonical snapd versions prior to 2.37.1.
https://github.com/coby-nguyen/Document-Linux-Privilege-Escalation
https://github.com/Live-Hack-CVE/CVE-2019-7304
https://github.com/elvi7major/snap_priv_esc
https://github.com/initstring/dirty_sock
https://www.exploit-db.com/exploits/46362