Search CVE reports


Toggle filters

1 – 10 of 96 results


CVE-2026-56854

Medium priority
Needs evaluation

The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions...

4 affected packages

golang-go.crypto, snapd, lxd, google-guest-agent

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-go.crypto Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
snapd Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
lxd Not in release Not in release Not in release Not affected Needs evaluation
google-guest-agent Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-66897

Medium priority
Needs evaluation

A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When...

1 affected package

lxd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lxd Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-55622

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name...

2 affected packages

incus, lxd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
incus Needs evaluation Needs evaluation Not in release
lxd Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-55621

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for custom volume copying where an attacker knowing the name of a project that they don't have access to and the...

2 affected packages

incus, lxd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
incus Needs evaluation Needs evaluation Not in release
lxd Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-48769

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead...

2 affected packages

incus, lxd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
incus Needs evaluation Needs evaluation Not in release
lxd Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-48756

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateCustomVolumeFromBackup` in `internal/server/storage/backend.go` contains an unguarded `*time.Time` dereference on the `ExpiresAt`...

2 affected packages

incus, lxd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
incus Needs evaluation Needs evaluation Not in release
lxd Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-48755

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an...

2 affected packages

incus, lxd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
incus Needs evaluation Needs evaluation Not in release
lxd Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-48752

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command...

2 affected packages

incus, lxd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
incus Needs evaluation Needs evaluation Not in release
lxd Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-48751

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on the Incus server by abusing...

2 affected packages

incus, lxd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
incus Needs evaluation Needs evaluation Not in release
lxd Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-48750

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the...

2 affected packages

incus, lxd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
incus Needs evaluation Needs evaluation Not in release
lxd Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages