Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

lxc — Vulnerabilities & Security Advisories 22

Browse all 22 CVE security advisories affecting lxc. AI-powered Chinese analysis, POCs, and references for each vulnerability.

LXC provides OS-level virtualization for running multiple isolated Linux systems on a single host. Historically, common vulnerabilities include remote code execution through container breakout flaws, privilege escalation via improper access controls, and cross-container information leaks. Notable security characteristics include its lightweight nature compared to full virtualization, though this can reduce isolation. Major incidents include CVE-2014-3707 allowing privilege escalation and CVE-2016-1587 enabling container escapes. With 22 CVEs on record, security risks often stem from misconfigurations or kernel vulnerabilities affecting container isolation. Proper hardening and kernel updates remain critical for secure deployment.

Found 20 results / 22Clear Filters
Top products by lxc: incus incus-os lxc
CVE IDTitleCVSSSeverityPublished
CVE-2026-41685 Incus: Unbounded binary import disk exhaustion — incusCWE-770 4.3 Medium2026-05-07
CVE-2026-41684 Incus: Nil Dereferences on Restore via Malformed YAML — incusCWE-476 6.5 Medium2026-05-07
CVE-2026-41648 Incus: Unbounded YAML Metadata Decode via Parsing — incusCWE-770 6.5AIMediumAI2026-05-07
CVE-2026-41647 Incus: Nil-Pointer Dereference via S3 Bucket Import — incusCWE-476 6.5 Medium2026-05-07
CVE-2026-40251 Incus out-of-bounds panic in snapshot metadata handling allows denial of service — incusCWE-129 6.5AIMediumAI2026-05-06
CVE-2026-40243 Incus OVN TLS verification accepts peer-supplied roots and permits endpoint impersonation — incusCWE-295 9.1AICriticalAI2026-05-06
CVE-2026-40197 Incus nil-pointer dereference in custom volume import allows denial of service — incusCWE-476 6.5AIMediumAI2026-05-06
CVE-2026-40195 Incus nil-pointer dereference in storage bucket import allows denial of service — incusCWE-476 6.5AIMediumAI2026-05-06
CVE-2026-35527 Incus blind SSRF via image import preflight HEAD request — incusCWE-918--2026-05-05
CVE-2026-33945 Abitrary file write through systemd-creds option — incusCWE-22 10.0 Critical2026-03-26
CVE-2026-33898 Local Incus UI web server vulnerable to nuthentication bypass — incusCWE-287 8.8 High2026-03-26
CVE-2026-33897 Incus vulnerable to arbitrary file read and write through pongo templates — incusCWE-1336 10.0 Critical2026-03-26
CVE-2026-33743 Incus vulnerable to denial of source through crafted bucket backup file — incusCWE-770 6.5 Medium2026-03-26
CVE-2026-33711 Incus vulnerable to local privilege escalation through VM screenshot path — incusCWE-61--2026-03-26
CVE-2026-33542 Incus does not verify combined fingerprint when downloading images from simplestreams servers — incusCWE-295 7.1 -2026-03-26
CVE-2026-23954 Incus container image templating arbitrary host file read and write — incusCWE-22 8.7 High2026-01-22
CVE-2026-23953 Incus container environment configuration newline injection — incusCWE-93 8.7 High2026-01-22
CVE-2025-64507 Incus vulnerable to local privilege escalation through custom storage volumes — incusCWE-269 8.8 -2025-11-10
CVE-2025-52890 Incus vulnerable to antispoofing nftables firewall rule bypass on bridge networks with ACLs — incusCWE-863 8.1 High2025-06-25
CVE-2025-52889 Incus vulnerable to DoS through antispoofing nftables firewall rule bypass on bridge networks with ACLs — incusCWE-770 3.4 Low2025-06-25

This page lists every published CVE security advisory associated with lxc. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.