vciy

CVEs we hold for Canonical

Records whose assigning authority named Canonical as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-9640LXD Snapshot Import Privilege Escalation VulnerabilityCanonical LXD
CVE-2026-9639Authenticated Denial of Service via Malicious Backup Tarball in LXDCanonical LXD
CVE-2026-9494ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure in Process Command LineCanonical Ubuntu 14.04 LTS
CVE-2026-8933snap-confine Local Privilege Escalation via Capabilities Misconfiguration or Flaw in Execution Environment SetupCanonical Ubuntu 22.04 LTS
CVE-2026-77113Path Traversal Vulnerability in apport-unpackCanonical Apport
CVE-2026-6970authd Denial of Service and Local Privilege EscalationCanonical authd
CVE-2026-66898Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCECanonical LXD
CVE-2026-66897Instance template path traversal allows arbitrary host file write as rootCanonical LXD
CVE-2026-6369Exposed Session Token in canonical-livepatch client snapcanonical-livepatch
CVE-2026-63300Cross-project instance move bypasses all project restrictions allowing host command executionCanonical LXD
CVE-2026-63299Storage volume cross-project move and snapshot restore bypass project disk limitsCanonical LXD
CVE-2026-63298LXD arbitrary lxc.conf directive injection via NVIDIA instance configurationCanonical LXD
CVE-2026-63297Cross-project instance copy bypasses target project restrictions via TOCTOU in config mergeCanonical LXD
CVE-2026-63296Project restriction bypass via instance migration config overrideCanonical LXD
CVE-2026-63295Project restriction `restricted.containers.privilege=isolated` bypassable by omitting `security.idmap.isolated`Canonical LXD
CVE-2026-63294Root RCE via image backup.yaml symlinkCanonical LXD
CVE-2026-63293Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as rootCanonical LXD
CVE-2026-62420Cross-project cluster migration bypasses project restrictions via cluster notification flagCanonical LXD
CVE-2026-61898accountsservice: shell injection via attacker-controlled ~/.pam_environment in Ubuntu language helper scriptsCanonical accountsservice
CVE-2026-61897accountsservice: incomplete privilege drop when running Ubuntu-specific language helper scriptsCanonical accountsservice
CVE-2026-5774Juju API Server Denial of Service and Authentication Replay via Unsynchronized Token MapCanonical Juju
CVE-2026-5412Juju CloudSpec API could leak senstive informationCanonical Juju
CVE-2026-49238SFTP Server VM Escape in Canonical MultipassCanonical Multipass
CVE-2026-49237Local Privilege Escalation in Canonical MultipassCanonical Multipass
CVE-2026-47337NULL pointer dereference in Ubuntu Linux AppArmor IPv4/IPv6 socket mediationCanonical Ubuntu Linux
CVE-2026-47336Use of uninitialized value in Ubuntu Linux AppArmor IPv4/IPv6 socket mediation rulesCanonical Ubuntu Linux
CVE-2026-47335NULL pointer dereference in Ubuntu Linux AppArmor notification handlingCanonical Ubuntu Linux
CVE-2026-47334Deadlock or kernel panic in Ubuntu Linux AppArmor notification handlingCanonical Ubuntu Linux
CVE-2026-47333Out-of-bounds read in Ubuntu Linux AppArmor notification handlingCanonical Ubuntu Linux
CVE-2026-47332Out-of-bounds read in Ubuntu Linux AppArmor notification handlingCanonical Ubuntu Linux
CVE-2026-47331Use-after-free in Ubuntu Linux AppArmor notification handlingCanonical Ubuntu Linux
CVE-2026-47330Use of uninitialized value in Ubuntu Linux AppArmor notification handlingCanonical Ubuntu Linux
CVE-2026-47329Incorrect validation of field size in Ubuntu Linux AppArmor notification responsesCanonical Ubuntu Linux
CVE-2026-47328Invalid pointer deallocation in Ubuntu Linux AppArmor notification handlingCanonical Ubuntu Linux
CVE-2026-47327NULL pointer dereference in Ubuntu Linux AppArmor notification handlingCanonical Ubuntu Linux
CVE-2026-47326Memory leak in Ubuntu Linux AppArmor large notification response allocationCanonical Ubuntu Linux
CVE-2026-4370Improper TLS Client/Server authentication and certificate verification on Database ClusterCanonical Juju
CVE-2026-3888Local Privilege Escalation in snapdCanonical Ubuntu 24.04 LTS
CVE-2026-34179Update of type field in restricted TLS certificate allows privilege escalation to cluster adminCanonical lxd
CVE-2026-34178Importing a crafted backup leads to project restriction bypassCanonical lxd
CVE-2026-34177VM lowlevel restriction bypass via raw.apparmor and raw.qemu.confCanonical lxd
CVE-2026-3351Authorization Bypass in LXD GET /1.0/certificates EndpointCanonical lxd
CVE-2026-32694Insecure Direct Object Reference attack via predictable secret ID in JujuCanonical Juju
CVE-2026-32693Unauthorized access to Kubernetes secrets in JujuCanonical Juju
CVE-2026-32692Unauthorized update of out-of-scope Vault secretsCanonical Juju
CVE-2026-32691Timing ownership claim attack on new external back-end secretsCanonical Juju
CVE-2026-28385SSRF via image import from URL allows internal network probing by authenticated usersCanonical lxd
CVE-2026-28384Authenticated RCE via unsanitized compression_algorithmCanonical lxd
CVE-2026-16033Arbitrary file read+write on host via templates/ symlink in malicious imageCanonical LXD
CVE-2026-15226snapd snap-confine Sandbox Confinement Bypass via Omission of setuid Restriction in Seccomp TemplatesCanonical Ubuntu 16.04 LTS
CVE-2026-12411Broken Access Control in Canonical LXD DevLXD APICanonical lxd
CVE-2026-12391ubuntu-pro-client Local Privilege Escalation and Information Disclosure via Symlink Arbitrary File Read in collect-logsCanonical Ubuntu 16.04 LTS
CVE-2026-1237no title heldCanonical juju
CVE-2026-12249Canonical ADSys Trust Store Poisoning via Plaintext HTTP Certificate Auto-EnrollmentCanonical Ubuntu 26.04 LTS
CVE-2026-11386ubuntu-pro-client Input Validation Vulnerability Leading to Arbitrary APT Directive Injection and Remote Code ExecutionCanonical Ubuntu 14.04 LTS
CVE-2026-10720MicroCeph path traversal issue in the remote-import APICanonical Microceph
CVE-2026-10037Sandbox Escape in Ubuntu OpenJDK Packages via xdg-desktop-portalCanonical Ubuntu
CVE-2025-6966Null-pointer dereference in python-apt TagSection.keys()Canonical python-apt
CVE-2025-6224Key leakage in juju/utils certificatesCanonical Juju utils
CVE-2025-5689Improper Permission Management in SSH Session HandlingCanonical authd
CVE-2025-5467Ubuntu Apport Insecure File Permissions VulnerabilityCanonical apport
CVE-2025-54293Path Traversal in LXD Instance Log File RetrievalCanonical LXD
CVE-2025-54292Client-Side Path Traversal in LXD-UICanonical LXD
CVE-2025-54291Project existence disclosure in LXD images APICanonical LXD
CVE-2025-54290Project Existence Disclosure via Error Handling in LXD Image ExportCanonical LXD
CVE-2025-54289Privilege Escalation via WebSocket Connection Hijacking in LXD Operations APICanonical LXD
CVE-2025-54288Source Container Identification Vulnerability via cmdline Spoofing in devLXD ServerCanonical LXD
CVE-2025-54287Arbitrary File Read via Template Injection in Snapshot PatternsCanonical LXD
CVE-2025-54286CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UICanonical LXD
CVE-2025-53513Zip slip vulnerability in JujuCanonical Juju
CVE-2025-53512Sensitive log retrieval in JujuCanonical Juju
CVE-2025-5199LPE on Multipass for macOSCanonical Multipass
CVE-2025-5054Race Condition in Canonical ApportCanonical Apport
CVE-2025-31479canonical/get-workflow-version-action can leak a partial GITHUB_TOKEN in exception outputcanonical get-workflow-version-action
CVE-2025-24375MySQL K8s charm could leak credentials for root-level user `serverconfig`canonical mysql-k8s-operator
CVE-2025-15480Senstive information disclosure was affecting ubuntu-desktop-provisionCanonical Ubuntu
CVE-2025-14551Senstive information disclosure was affecting subiquityCanonical Ubuntu
CVE-2025-13350Use-after-free of orphaned AF_UNIX in Ubuntu builds of Linux kernelCanonical Ubuntu Linux
CVE-2025-0928Arbitrary executable upload via authenticated endpointCanonical Juju
CVE-2024-9313no title heldCanonical Ltd. Authd
CVE-2024-9312no title heldCanonical Ltd. Authd
CVE-2024-8287no title heldCanonical Ltd. Anbox Cloud
CVE-2024-8038no title heldCanonical Ltd. Juju
CVE-2024-8037no title heldCanonical Ltd. Juju
CVE-2024-7558no title heldCanonical Ltd. Juju
CVE-2024-6984no title heldCanonical Ltd. Juju
CVE-2024-6714no title heldCanonical Ltd. Ubuntu Desktop Provision
CVE-2024-6388no title heldCanonical Ltd. Ubuntu Advantage Desktop Pro
CVE-2024-6219no title heldCanonical Ltd. LXD
CVE-2024-6174no title heldCanonical cloud-init
CVE-2024-6156no title heldCanonical Ltd. LXD
CVE-2024-6107no title heldCanonical MAAS
CVE-2024-5300AppArmor Base Profile Misconfiguration in snapd Permits Confined Snaps Unauthorized Access to Hashed Passwords via…Canonical Ubuntu 16.04 LTS
CVE-2024-5290no title heldCanonical Ltd. wpa_supplicant
CVE-2024-5138no title heldCanonical Ltd. snapd
CVE-2024-41129The ops library leaks secrets if `subprocess.CalledProcessError` happens with a `secret-*` CLI commandcanonical operator
CVE-2024-3250no title heldCanonical Ltd. Pebble
CVE-2024-29069snapd will follow archived symlinks when unpacking a filesystemCanonical snapd
CVE-2024-29068snapd non-regular file indefinite blocking readCanonical snapd
CVE-2024-1724snapd allows $HOME/bin symlinkCanonical snap
CVE-2024-11586no title heldCanonical Ltd. Ubuntu's pulseaudio
CVE-2024-11584no title heldCanonical cloud-init
CVE-2023-5616no title heldCanonical Ltd. Ubuntu's gnome-control-center
CVE-2023-5536no title heldCanonical Ubuntu Server
CVE-2023-5182no title heldCanonical Ltd. subiquity
CVE-2023-49721no title heldCanonical Ltd. LXD
CVE-2023-48733no title heldCanonical Ltd. Ubuntu EDK II
CVE-2023-3297no title heldCanonical Ltd. AccountService
CVE-2023-32629no title heldCanonical Ubuntu Kernel
CVE-2023-32551Landscape Open RedirectCanonical Ltd. Landscape
CVE-2023-32550Landscape's Apache server-status is accessible by defaultCanonical Ltd. Landscape
CVE-2023-32549Landscape insecure token generationCanonical Ltd. Landscape
CVE-2023-2640no title heldCanonical Ubuntu Kernel
CVE-2023-2612shiftfs lock unbalance in Ubuntu-specific kernelsCanonical Ltd. ubuntu-linux
CVE-2023-1786sensitive data exposure in cloud-init logsCanonical Ltd. cloud-init
CVE-2023-1523no title heldCanonical Ltd. snapd
CVE-2023-1326local privilege escalation in apport-cliCanonical Ltd. Apport
CVE-2023-0092no title heldCanonical Ltd. Juju
CVE-2022-4968no title heldCanonical Ltd. Netplan
CVE-2022-4964no title heldCanonical Ltd. Ubuntu pipewire-pulse
CVE-2022-3328no title heldCanonical Ltd. snapd
CVE-2022-28658no title heldCanonical Ltd. Apport
CVE-2022-28657no title heldCanonical Ltd. Apport
CVE-2022-28656no title heldCanonical Ltd. Apport
CVE-2022-28655no title heldCanonical Ltd. Apport
CVE-2022-28654no title heldCanonical Ltd. Apport
CVE-2022-28653no title heldCanonical Ltd. Apport
CVE-2022-28652no title heldCanonical Ltd. Apport
CVE-2022-2084sensitive data exposure in cloud-init logsCanonical Ltd. cloud-init
CVE-2022-1736no title heldCanonical Ltd. Ubuntu's gnome-control-center
CVE-2022-1242no title heldCanonical Ltd. Apport
CVE-2022-0555no title heldCanonical Ltd. subiquity
CVE-2021-44731snapd could be made to escalate privileges and run programs as administratorCanonical Ltd. snapd
CVE-2021-44730snapd could be made to escalate privileges and run programs as administratorCanonical Ltd. snapd
CVE-2021-4120snapd could be made to bypass intended access restrictions through snap content interfaces and layout pathsCanonical Ltd. snapd
CVE-2021-3899no title heldCanonical Ltd. Apport
CVE-2021-3747MacOS version of Multipass incorrect owner for application directoryCanonical Multipass
CVE-2021-3710Apport info disclosure via path traversal bug in read_fileCanonical apport
CVE-2021-3709Apport file permission bypass through emacs byte compilation errorsCanonical apport
CVE-2021-3626Windows version of Multipass unauthenticated localhost tcp control socket can perform mountsCanonical Multipass
CVE-2021-3429sensitive data exposure in cloud-init logsCanonical Ltd. cloud-init
CVE-2021-32557apport process_report() arbitrary file writeCanonical apport
CVE-2021-32556apport get_modified_conffiles() function command injectionCanonical apport
CVE-2021-32555apport read_file() function could follow maliciously constructed symbolic linksCanonical apport
CVE-2021-32554apport read_file() function could follow maliciously constructed symbolic linksCanonical apport
CVE-2021-32553apport read_file() function could follow maliciously constructed symbolic linksCanonical apport
CVE-2021-32552apport read_file() function could follow maliciously constructed symbolic linksCanonical apport
CVE-2021-32551apport read_file() function could follow maliciously constructed symbolic linksCanonical apport
CVE-2021-32550apport read_file() function could follow maliciously constructed symbolic linksCanonical apport
CVE-2021-32549apport read_file() function could follow maliciously constructed symbolic linksCanonical apport
CVE-2021-32548apport read_file() function could follow maliciously constructed symbolic linksCanonical apport
CVE-2021-32547apport read_file() function could follow maliciously constructed symbolic linksCanonical apport
CVE-2021-3155snapd created ~/snap with too-wide permissionsCanonical Ltd. snapd
CVE-2021-25684apport can be stalled by reading a FIFOCanonical apport
CVE-2021-25683apport improperly parses /proc/pid/statCanonical apport
CVE-2021-25682apport improperly parses /proc/pid/statusCanonical apport
CVE-2020-8833Apport race condition in crash report permissionsCanonical Apport
CVE-2020-8831World writable root owned lock file created in user controllable locationCanonical Apport
CVE-2020-27352no title heldCanonical Ltd. snapd
CVE-2020-27351Various memory and file descriptor leaks in apt-pythonCanonical python-apt
CVE-2020-27350apt integer wraparoundCanonical apt
CVE-2020-27349aptdaemon performed policykit permissions checks too lateCanonical aptdaemon
CVE-2020-27348snapcraft may build snaps with incorrect LD_LIBRARY_PATHCanonical snapcraft
CVE-2020-16128Aptdaemon error messages disclosed file existence to unprivileged users via dbus propertiesCanonical aptdaemon
CVE-2020-16123Bypass of snapd pulseaudio restrictionsCanonical pulseaudio
CVE-2020-16119DCCP CCID structure use-after-freeCanonical Linux kernel
CVE-2020-15710Potential double-free in pulseaudioCanonical PulseAudio
CVE-2020-15709add-apt-repository print ASNI terminal codesCanonical add-apt-repository
CVE-2020-15704pppd arbitrary file read information disclosure vulnerabilityCanonical ppp
CVE-2020-15703aptdaemon allows unprivileged users to test for the presence of local files via the transaction Locale propertyCanonical aptdaemon
CVE-2020-15702TOCTOU in apportCanonical apport
CVE-2020-15701Unhandled exception in apportCanonical apport
CVE-2020-11937Resource exhaustion vulnerability in whoopsieCanonical whoopsie
CVE-2020-11936no title heldCanonical Ltd. Apport
CVE-2020-11934Sandbox escape vulnerability via snapctl user-open (xdg-open)Canonical snapd
CVE-2020-11933local snapd exploit through cloud-initCanonical core
CVE-2020-11932Subiquity server installer logged LUKS full disk encryption passwordCanonical Subiquity
CVE-2020-11931Ubuntu modifications to pulseaudio to provide snap security enforcement could be unloadedCanonical pulseaudio
CVE-2019-7306Byobu apport hook uploads user's ~/.screenrcCanonical byobu
CVE-2019-7305eXtplorer exposes /usr and /etc/extplorer over HTTPCanonical eXtplorer
CVE-2019-7304Local privilege escalation via snapd socketCanonical snapd
CVE-2019-7303Snapd seccomp filter TIOCSTI ioctl bypassCanonical snapd
CVE-2019-15796python-apt downloads from untrusted sourcesCanonical Python-apt
CVE-2019-15795python-apt uses MD5 for validationCanonical Python-apt
CVE-2019-15790Apport reads PID files with elevated privilegesCanonical Apport
CVE-2019-15789Microk8s Privilege Escalation VulnerabilityCanonical MicroK8s
CVE-2019-11485apport created lock file in wrong directoryCanonical apport
CVE-2019-11484Integer overflow in bson_ensure_spaceCanonical whoopsie
CVE-2019-11483no title heldCanonical apport
CVE-2019-11482Race condition between reading current working directory and writing a core dumpCanonical apport
CVE-2019-11481Apport reads arbitrary files if ~/.config/apport/settings is a symlinkCanonical apport
CVE-2019-11480Ubuntu kernel snap build process could use unauthenticated sourcesCanonical pc-kernel
CVE-2018-6559no title heldCanonical Ltd. Linux kernel, as used in Ubuntu 18.04 LTS…
CVE-2018-10896no title heldCanonical cloud-init
CVE-2015-7946MTP service exposed during emergency dialerCanonical unity8 (Ubuntu)
CVE-2014-1422Location service uses cached authorization even after revocationCanonical trust-store (Ubuntu RTM)
CVE-2014-1420Insecure temp file usage in Ubuntu UI toolkitCanonical ubuntu-ui-toolkit
CVE-2013-1055Potential DoS through abuse of rate limit in libunity-webapps for FirefoxCanonical libunity-webapps
CVE-2013-1054Possible remote DOS in WebAppsCanonical unity-firefox-extension
CVE-2013-1053Insecure crypto for storing passwordsCanonical remote-login-service

200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.