vendor

canonical

16 thingsrelated by NVD

Its products

lxd 12 ubuntu linux 2 ubuntu desktop provision 1 ubuntu subiquity 1

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When…
CVE-2026-66898
Severity critical
A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user…
CVE-2026-66897
Severity critical
An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker…
CVE-2026-63300
Severity critical
An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code…
CVE-2026-63299
Severity critical
An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated…
CVE-2026-63298
Severity critical
An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass…
CVE-2026-63297
Severity critical
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance…
CVE-2026-63296
Severity critical
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions…
CVE-2026-63295
Severity medium
A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or…
CVE-2026-63294
Severity critical
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during…
CVE-2026-62420
Severity critical
An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute…
CVE-2026-28384
Severity critical
A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When…
CVE-2026-16033
Severity high
In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation…
CVE-2025-15480
Severity critical
In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user…
CVE-2025-14551
Severity high
python-apt: python-apt: NULL pointer dereference leads to local denial of service
CVE-2025-6966
Severity medium
A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the…
CVE-2023-1380
Severity high