Search CVE reports


Toggle filters

1 – 10 of 52 results


CVE-2026-34179

Medium priority
Needs evaluation

In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PUT/PATCH requests to /1.0/certificates/{fingerprint} for restricted TLS...

2 affected packages

incus, lxd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
incus Needs evaluation Not in release
lxd Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-34178

Medium priority
Needs evaluation

In Canonical LXD before 6.8, the backup import path validates project restrictions against backup/index.yaml in the supplied tar archive but creates the instance from backup/container/backup.yaml, a separate file in the same...

2 affected packages

incus, lxd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
incus Needs evaluation Not in release
lxd Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-34177

Medium priority
Needs evaluation

Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limits/permissions.go), which omits raw.apparmor and raw.qemu.conf from the set of keys blocked under...

2 affected packages

incus, lxd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
incus Needs evaluation Not in release
lxd Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-33945

High priority
Needs evaluation

Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to systemd in the guest. For containers, this is handled through a shared directory. Prior to version 6.23.0, an...

2 affected packages

incus, lxd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
incus Needs evaluation Not in release
lxd Not in release Not in release Not affected Not affected
Show less packages

CVE-2026-33898

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui` incorrectly validates the authentication token such that an invalid value will be accepted. `incus webui`...

2 affected packages

incus, lxd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
incus Needs evaluation Not in release
lxd Not in release Not in release Not affected Not affected
Show less packages

CVE-2026-33897

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 6.23.0, instance template files can be used to cause arbitrary read or writes as root on the host server. Incus allows for pongo2 templates within instances...

2 affected packages

incus, lxd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
incus Needs evaluation Not in release
lxd Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-33743

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket backup can be used by an user with access to Incus' storage bucket feature to crash the Incus daemon. Repeated...

2 affected packages

incus, lxd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
incus Needs evaluation Not in release
lxd Not in release Not in release Not affected Not affected
Show less packages

CVE-2026-33711

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Incus provides an API to retrieve VM screenshots. That API relies on the use of a temporary file for QEMU to write the screenshot to which is then picked up and sent to the...

2 affected packages

incus, lxd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
incus Needs evaluation Not in release
lxd Not in release Not in release Not affected Not affected
Show less packages

CVE-2026-33542

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 6.23.0, a lack of validation of the image fingerprint when downloading from simplestreams image servers opens the door to image cache poisoning and under...

2 affected packages

incus, lxd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
incus Needs evaluation Not in release
lxd Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-28384

Medium priority
Not affected

An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup endpoints....

1 affected package

lxd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lxd Not in release Not in release Not affected Not affected
Show less packages