vciy

CVEs we hold for Lxc

Records whose assigning authority named Lxc as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-63343Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as rootlxc incus
CVE-2026-63125Incus vulnerable to root RCE via image backup.yaml symlinklxc incus
CVE-2026-62941Incus: Cross-project instance copy bypasses target project restrictions via TOCTOU in config mergelxc incus
CVE-2026-62940Incus has a project restriction bypass via instance migration config overridelxc incus
CVE-2026-62867Incus has an argument injection in storage volume block.create_options that leads to arbitrary command executionlxc incus
CVE-2026-62313Incus: Project restriction `restricted.containers.privilege=isolated` bypassable by omitting `security.idmap.isolated`lxc incus
CVE-2026-55622Incus has a project restriction bypass in instance copy across projectslxc incus
CVE-2026-55621Incus has a project restriction bypass for custom volume copy across projectslxc incus
CVE-2026-52727lxc-ci: Pacman keyring stored in archlinux image with a private keylxc-ci
CVE-2026-48769Incus has an arbitrary file write on its client due to trusted image hashlxc incus
CVE-2026-48756Incus: CreateCustomVolumeFromBackup nil-pointer dereference on volume_snapshots[*].expires_at (sibling-field variant of…lxc incus
CVE-2026-48755Incus has an argument injection in backup compression algorithm leading to AFW and ACElxc incus
CVE-2026-48754Incus: Nil-pointer dereference in createDependentVolumesFromBackup on disk.{Volume,VolumeSnapshots,Pool}lxc incus
CVE-2026-48753Incus has an arbitrary file write via path traversal in S3 multipart uploadlxc incus
CVE-2026-48752Incus has arbitrary file read+write on host via templates/ symlink in malicious imagelxc incus
CVE-2026-48751Incus has a restricted project bypass leading to arbitrary command executionlxc incus
CVE-2026-48750Incus has an arbitrary file write on host via `exec-output` symlink in crafted imagelxc incus
CVE-2026-48749Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious imagelxc incus
CVE-2026-47753Incus has a Nil-Pointer Dereference Panic via Instance Backup Import (volume omitted)lxc incus
CVE-2026-41685Incus: Unbounded binary import disk exhaustionlxc incus
CVE-2026-41684Incus: Nil Dereferences on Restore via Malformed YAMLlxc incus
CVE-2026-41648Incus: Unbounded YAML Metadata Decode via Parsinglxc incus
CVE-2026-41647Incus: Nil-Pointer Dereference via S3 Bucket Importlxc incus
CVE-2026-40251Incus out-of-bounds panic in snapshot metadata handling allows denial of servicelxc incus
CVE-2026-40243Incus OVN TLS verification accepts peer-supplied roots and permits endpoint impersonationlxc incus
CVE-2026-40197Incus nil-pointer dereference in custom volume import allows denial of servicelxc incus
CVE-2026-40195Incus nil-pointer dereference in storage bucket import allows denial of servicelxc incus
CVE-2026-39402lxc lxc-user-nic insufficient ownership validation allows cross-tenant OVS port deletionlxc
CVE-2026-35527Incus blind SSRF via image import preflight HEAD requestlxc incus
CVE-2026-33945Abitrary file write through systemd-creds optionlxc incus
CVE-2026-33898Local Incus UI web server vulnerable to nuthentication bypasslxc incus
CVE-2026-33897Incus vulnerable to arbitrary file read and write through pongo templateslxc incus
CVE-2026-33743Incus vulnerable to denial of source through crafted bucket backup filelxc incus
CVE-2026-33711Incus vulnerable to local privilege escalation through VM screenshot pathlxc incus
CVE-2026-33542Incus does not verify combined fingerprint when downloading images from simplestreams serverslxc incus
CVE-2026-32606IncusOS has a LUKS encryption bypass due to insufficient TPM policylxc incus-os
CVE-2026-23954Incus container image templating arbitrary host file read and writelxc incus
CVE-2026-23953Incus container environment configuration newline injectionlxc incus
CVE-2025-64507Incus vulnerable to local privilege escalation through custom storage volumeslxc incus
CVE-2025-52890Incus vulnerable to antispoofing nftables firewall rule bypass on bridge networks with ACLslxc incus
CVE-2025-52889Incus vulnerable to DoS through antispoofing nftables firewall rule bypass on bridge networks with ACLslxc incus
CVE-2018-6556The lxc-user-nic component of LXC allows unprivileged users to open arbitrary filesn/a LXC
CVE-2016-8649no title heldn/a LXC before 1.0.9 and 2.x before 2.0.6
CVE-2014-125123Kloxo < 6.1.12 Unauthenticated SQL Injection RCELXCenter Kloxo
CVE-2012-10022Kloxo <= 6.1.12 Local Privilege EscalationLxCenter Kloxo

45 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.