CVEs we hold for Canonical
Records whose assigning authority named Canonical as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-9494ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure in Process Command LineCanonical Ubuntu 14.04 LTS
CVE-2026-8933snap-confine Local Privilege Escalation via Capabilities Misconfiguration or Flaw in Execution Environment SetupCanonical Ubuntu 22.04 LTS
CVE-2026-66898Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCECanonical LXD
CVE-2026-66897Instance template path traversal allows arbitrary host file write as rootCanonical LXD
CVE-2026-63300Cross-project instance move bypasses all project restrictions allowing host command executionCanonical LXD
CVE-2026-63299Storage volume cross-project move and snapshot restore bypass project disk limitsCanonical LXD
CVE-2026-63298LXD arbitrary lxc.conf directive injection via NVIDIA instance configurationCanonical LXD
CVE-2026-63297Cross-project instance copy bypasses target project restrictions via TOCTOU in config mergeCanonical LXD
CVE-2026-63295Project restriction `restricted.containers.privilege=isolated` bypassable by omitting `security.idmap.isolated`Canonical LXD
CVE-2026-63293Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as rootCanonical LXD
CVE-2026-62420Cross-project cluster migration bypasses project restrictions via cluster notification flagCanonical LXD
CVE-2026-61898accountsservice: shell injection via attacker-controlled ~/.pam_environment in Ubuntu language helper scriptsCanonical accountsservice
CVE-2026-61897accountsservice: incomplete privilege drop when running Ubuntu-specific language helper scriptsCanonical accountsservice
CVE-2026-5774Juju API Server Denial of Service and Authentication Replay via Unsynchronized Token MapCanonical Juju
CVE-2026-47337NULL pointer dereference in Ubuntu Linux AppArmor IPv4/IPv6 socket mediationCanonical Ubuntu Linux
CVE-2026-47336Use of uninitialized value in Ubuntu Linux AppArmor IPv4/IPv6 socket mediation rulesCanonical Ubuntu Linux
CVE-2026-47335NULL pointer dereference in Ubuntu Linux AppArmor notification handlingCanonical Ubuntu Linux
CVE-2026-47334Deadlock or kernel panic in Ubuntu Linux AppArmor notification handlingCanonical Ubuntu Linux
CVE-2026-47333Out-of-bounds read in Ubuntu Linux AppArmor notification handlingCanonical Ubuntu Linux
CVE-2026-47332Out-of-bounds read in Ubuntu Linux AppArmor notification handlingCanonical Ubuntu Linux
CVE-2026-47330Use of uninitialized value in Ubuntu Linux AppArmor notification handlingCanonical Ubuntu Linux
CVE-2026-47329Incorrect validation of field size in Ubuntu Linux AppArmor notification responsesCanonical Ubuntu Linux
CVE-2026-47328Invalid pointer deallocation in Ubuntu Linux AppArmor notification handlingCanonical Ubuntu Linux
CVE-2026-47327NULL pointer dereference in Ubuntu Linux AppArmor notification handlingCanonical Ubuntu Linux
CVE-2026-47326Memory leak in Ubuntu Linux AppArmor large notification response allocationCanonical Ubuntu Linux
CVE-2026-4370Improper TLS Client/Server authentication and certificate verification on Database ClusterCanonical Juju
CVE-2026-34179Update of type field in restricted TLS certificate allows privilege escalation to cluster adminCanonical lxd
CVE-2026-32694Insecure Direct Object Reference attack via predictable secret ID in JujuCanonical Juju
CVE-2026-28385SSRF via image import from URL allows internal network probing by authenticated usersCanonical lxd
CVE-2026-16033Arbitrary file read+write on host via templates/ symlink in malicious imageCanonical LXD
CVE-2026-15226snapd snap-confine Sandbox Confinement Bypass via Omission of setuid Restriction in Seccomp TemplatesCanonical Ubuntu 16.04 LTS
CVE-2026-12391ubuntu-pro-client Local Privilege Escalation and Information Disclosure via Symlink Arbitrary File Read in collect-logsCanonical Ubuntu 16.04 LTS
CVE-2026-12249Canonical ADSys Trust Store Poisoning via Plaintext HTTP Certificate Auto-EnrollmentCanonical Ubuntu 26.04 LTS
CVE-2026-11386ubuntu-pro-client Input Validation Vulnerability Leading to Arbitrary APT Directive Injection and Remote Code ExecutionCanonical Ubuntu 14.04 LTS
CVE-2025-54289Privilege Escalation via WebSocket Connection Hijacking in LXD Operations APICanonical LXD
CVE-2025-54288Source Container Identification Vulnerability via cmdline Spoofing in devLXD ServerCanonical LXD
CVE-2025-54286CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UICanonical LXD
CVE-2025-31479canonical/get-workflow-version-action can leak a partial GITHUB_TOKEN in exception outputcanonical get-workflow-version-action
CVE-2025-24375MySQL K8s charm could leak credentials for root-level user `serverconfig`canonical mysql-k8s-operator
CVE-2025-15480Senstive information disclosure was affecting ubuntu-desktop-provisionCanonical Ubuntu
CVE-2025-13350Use-after-free of orphaned AF_UNIX in Ubuntu builds of Linux kernelCanonical Ubuntu Linux
CVE-2024-5300AppArmor Base Profile Misconfiguration in snapd Permits Confined Snaps Unauthorized Access to Hashed Passwords via…Canonical Ubuntu 16.04 LTS
CVE-2024-41129The ops library leaks secrets if `subprocess.CalledProcessError` happens with a `secret-*` CLI commandcanonical operator
CVE-2021-44731snapd could be made to escalate privileges and run programs as administratorCanonical Ltd. snapd
CVE-2021-44730snapd could be made to escalate privileges and run programs as administratorCanonical Ltd. snapd
CVE-2021-4120snapd could be made to bypass intended access restrictions through snap content interfaces and layout pathsCanonical Ltd. snapd
CVE-2021-3747MacOS version of Multipass incorrect owner for application directoryCanonical Multipass
CVE-2021-3626Windows version of Multipass unauthenticated localhost tcp control socket can perform mountsCanonical Multipass
CVE-2021-32555apport read_file() function could follow maliciously constructed symbolic linksCanonical apport
CVE-2021-32554apport read_file() function could follow maliciously constructed symbolic linksCanonical apport
CVE-2021-32553apport read_file() function could follow maliciously constructed symbolic linksCanonical apport
CVE-2021-32552apport read_file() function could follow maliciously constructed symbolic linksCanonical apport
CVE-2021-32551apport read_file() function could follow maliciously constructed symbolic linksCanonical apport
CVE-2021-32550apport read_file() function could follow maliciously constructed symbolic linksCanonical apport
CVE-2021-32549apport read_file() function could follow maliciously constructed symbolic linksCanonical apport
CVE-2021-32548apport read_file() function could follow maliciously constructed symbolic linksCanonical apport
CVE-2021-32547apport read_file() function could follow maliciously constructed symbolic linksCanonical apport
CVE-2020-8831World writable root owned lock file created in user controllable locationCanonical Apport
CVE-2020-16128Aptdaemon error messages disclosed file existence to unprivileged users via dbus propertiesCanonical aptdaemon
CVE-2020-15703aptdaemon allows unprivileged users to test for the presence of local files via the transaction Locale propertyCanonical aptdaemon
CVE-2020-11932Subiquity server installer logged LUKS full disk encryption passwordCanonical Subiquity
CVE-2020-11931Ubuntu modifications to pulseaudio to provide snap security enforcement could be unloadedCanonical pulseaudio
CVE-2019-11482Race condition between reading current working directory and writing a core dumpCanonical apport
CVE-2019-11481Apport reads arbitrary files if ~/.config/apport/settings is a symlinkCanonical apport
CVE-2014-1422Location service uses cached authorization even after revocationCanonical trust-store (Ubuntu RTM)
CVE-2013-1055Potential DoS through abuse of rate limit in libunity-webapps for FirefoxCanonical libunity-webapps
200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.