Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Canonical — Vulnerabilities & Security Advisories 141

Browse all 141 CVE security advisories affecting Canonical. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Canonical Ltd. primarily develops and maintains Ubuntu, a widely deployed Linux distribution, alongside the OpenStack cloud infrastructure platform and the Snap package management system. Security audits reveal a significant volume of recorded vulnerabilities, currently totaling 107 CVEs, reflecting the extensive codebase and third-party dependencies inherent in these large-scale software ecosystems. Historically, the most prevalent vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from improper input validation or insecure default configurations within associated services. While no single catastrophic incident has defined the company’s security history, the sheer number of disclosed issues highlights the challenges of maintaining rigorous patch cycles across diverse components. These findings underscore the necessity for continuous monitoring and timely updates for organizations relying on Canonical’s open-source technologies to mitigate potential exploitation risks.

CVE IDTitleCVSSSeverityPublished
CVE-2026-16033 Arbitrary file read+write on host via templates/ symlink in malicious image — LXDCWE-22 8.5 High2026-08-12
CVE-2026-66898 Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE — LXDCWE-22 9.9 Critical2026-08-12
CVE-2026-63293 Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root — LXDCWE-59 9.9 Critical2026-08-12
CVE-2026-63294 Root RCE via image backup.yaml symlink — LXDCWE-59 9.9 Critical2026-08-12
CVE-2026-63295 Project restriction `restricted.containers.privilege=isolated` bypassable by omitting `security.idmap.isolated` — LXDCWE-863 4.3 Medium2026-08-12
CVE-2026-63296 Project restriction bypass via instance migration config override — LXDCWE-863 9.9 Critical2026-08-12
CVE-2026-63297 Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge — LXDCWE-367 9.9 Critical2026-08-12
CVE-2026-63298 LXD arbitrary lxc.conf directive injection via NVIDIA instance configuration — LXDCWE-78 8.7 Critical2026-08-12
CVE-2026-63299 Storage volume cross-project move and snapshot restore bypass project disk limits — LXDCWE-770 8.5 Critical2026-08-12
CVE-2026-62420 Cross-project cluster migration bypasses project restrictions via cluster notification flag — LXDCWE-863 9.9 Critical2026-08-12
CVE-2026-63300 Cross-project instance move bypasses all project restrictions allowing host command execution — LXDCWE-862 9.9 Critical2026-08-12
CVE-2026-12391 ubuntu-pro-client Local Privilege Escalation and Information Disclosure via Symlink Arbitrary File Read in collect-logs — ubuntu-pro-client (ubuntu-advantage-tools)CWE-59 5.0 Medium2026-07-16
CVE-2026-11386 ubuntu-pro-client Input Validation Vulnerability Leading to Arbitrary APT Directive Injection and Remote Code Execution — ubuntu-pro-client (ubuntu-advantage-tools)CWE-20 9.0 Critical2026-07-16
CVE-2026-9494 ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure in Process Command Line — ubuntu-pro-client (ubuntu-advantage-tools)CWE-214 5.5 Medium2026-07-16
CVE-2026-10037 Sandbox Escape in Ubuntu OpenJDK Packages via xdg-desktop-portal — UbuntuCWE-20 8.8 High2026-07-08
CVE-2026-28385 SSRF via image import from URL allows internal network probing by authenticated users — lxdCWE-918 5.0 Medium2026-06-26
CVE-2026-9640 LXD Snapshot Import Privilege Escalation Vulnerability — LXDCWE-863 7.2 High2026-06-26
CVE-2026-9639 Authenticated Denial of Service via Malicious Backup Tarball in LXD — LXDCWE-476 6.5 Medium2026-06-26
CVE-2026-12411 Broken Access Control in Canonical LXD DevLXD API — lxdCWE-639 8.4 High2026-06-26
CVE-2026-10720 MicroCeph path traversal issue in the remote-import API — MicrocephCWE-23--2026-06-19
CVE-2026-47337 NULL pointer dereference in Ubuntu Linux AppArmor IPv4/IPv6 socket mediation — Ubuntu LinuxCWE-476 3.3 Low2026-05-28
CVE-2026-47336 Use of uninitialized value in Ubuntu Linux AppArmor IPv4/IPv6 socket mediation rules — Ubuntu LinuxCWE-457 3.3 Low2026-05-28
CVE-2026-47335 NULL pointer dereference in Ubuntu Linux AppArmor notification handling — Ubuntu LinuxCWE-476 5.5 Medium2026-05-28
CVE-2026-47334 Deadlock or kernel panic in Ubuntu Linux AppArmor notification handling — Ubuntu LinuxCWE-833 5.5 Medium2026-05-28
CVE-2026-47333 Out-of-bounds read in Ubuntu Linux AppArmor notification handling — Ubuntu LinuxCWE-125 7.8 High2026-05-28
CVE-2026-47332 Out-of-bounds read in Ubuntu Linux AppArmor notification handling — Ubuntu LinuxCWE-125 5.5 Medium2026-05-28
CVE-2026-47331 Use-after-free in Ubuntu Linux AppArmor notification handling — Ubuntu LinuxCWE-416 7.8 High2026-05-28
CVE-2026-47330 Use of uninitialized value in Ubuntu Linux AppArmor notification handling — Ubuntu LinuxCWE-457 3.3 Low2026-05-28
CVE-2026-47329 Incorrect validation of field size in Ubuntu Linux AppArmor notification responses — Ubuntu LinuxCWE-1284 3.3 Low2026-05-28
CVE-2026-47328 Invalid pointer deallocation in Ubuntu Linux AppArmor notification handling — Ubuntu LinuxCWE-590 6.1 Medium2026-05-28

This page lists every published CVE security advisory associated with Canonical. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.