CVEs we hold for Lxc
Records whose assigning authority named Lxc as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-63343Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as rootlxc incus
CVE-2026-62941Incus: Cross-project instance copy bypasses target project restrictions via TOCTOU in config mergelxc incus
CVE-2026-62940Incus has a project restriction bypass via instance migration config overridelxc incus
CVE-2026-62867Incus has an argument injection in storage volume block.create_options that leads to arbitrary command executionlxc incus
CVE-2026-62313Incus: Project restriction `restricted.containers.privilege=isolated` bypassable by omitting `security.idmap.isolated`lxc incus
CVE-2026-55621Incus has a project restriction bypass for custom volume copy across projectslxc incus
CVE-2026-48756Incus: CreateCustomVolumeFromBackup nil-pointer dereference on volume_snapshots[*].expires_at (sibling-field variant of…lxc incus
CVE-2026-48755Incus has an argument injection in backup compression algorithm leading to AFW and ACElxc incus
CVE-2026-48754Incus: Nil-pointer dereference in createDependentVolumesFromBackup on disk.{Volume,VolumeSnapshots,Pool}lxc incus
CVE-2026-48752Incus has arbitrary file read+write on host via templates/ symlink in malicious imagelxc incus
CVE-2026-48750Incus has an arbitrary file write on host via `exec-output` symlink in crafted imagelxc incus
CVE-2026-48749Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious imagelxc incus
CVE-2026-47753Incus has a Nil-Pointer Dereference Panic via Instance Backup Import (volume omitted)lxc incus
CVE-2026-40251Incus out-of-bounds panic in snapshot metadata handling allows denial of servicelxc incus
CVE-2026-40243Incus OVN TLS verification accepts peer-supplied roots and permits endpoint impersonationlxc incus
CVE-2026-40197Incus nil-pointer dereference in custom volume import allows denial of servicelxc incus
CVE-2026-40195Incus nil-pointer dereference in storage bucket import allows denial of servicelxc incus
CVE-2026-39402lxc lxc-user-nic insufficient ownership validation allows cross-tenant OVS port deletionlxc
CVE-2026-33542Incus does not verify combined fingerprint when downloading images from simplestreams serverslxc incus
CVE-2025-64507Incus vulnerable to local privilege escalation through custom storage volumeslxc incus
CVE-2025-52890Incus vulnerable to antispoofing nftables firewall rule bypass on bridge networks with ACLslxc incus
CVE-2025-52889Incus vulnerable to DoS through antispoofing nftables firewall rule bypass on bridge networks with ACLslxc incus
CVE-2018-6556The lxc-user-nic component of LXC allows unprivileged users to open arbitrary filesn/a LXC
45 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.