Search CVE reports


Toggle filters

231 – 240 of 50365 results

Status is adjusted based on your filters.


CVE-2026-87799

Medium priority
Needs evaluation

Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes...

1 affected package

lxd

Package 20.04 LTS
lxd Needs evaluation
Show less packages

CVE-2026-87798

Medium priority
Needs evaluation

Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.0.2 up to 6.9 (fixed in 4.0.14, 5.0.10 and 5.21.8) on Linux allows an attacker with root access inside a virtual machine...

1 affected package

lxd

Package 20.04 LTS
lxd Needs evaluation
Show less packages

CVE-2026-86335

Medium priority
Needs evaluation

Missing Authorization in imageDownload in Canonical LXD before 5.0.10, 5.21.8, and 6.10 on Linux allows a project-restricted client to access private images from other projects via local fingerprint reuse during image or instance...

1 affected package

lxd

Package 20.04 LTS
lxd Needs evaluation
Show less packages

CVE-2026-86334

Medium priority
Needs evaluation

Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms allows a remote malicious or machine-in-the-middle image server to overwrite...

1 affected package

lxd

Package 20.04 LTS
lxd Needs evaluation
Show less packages

CVE-2026-85526

Medium priority
Needs evaluation

Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root...

2 affected packages

incus, lxd

Package 20.04 LTS
incus —
lxd Needs evaluation
Show less packages

CVE-2026-85185

Medium priority
Needs evaluation

Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete...

2 affected packages

incus, lxd

Package 20.04 LTS
incus —
lxd Needs evaluation
Show less packages

CVE-2026-94287

Medium priority
Needs evaluation

A denial of service via unsigned underflow in libXpm's write path in libXpm before 3.5.19 could be used by local attackers to cause unbounded CPU usage and memory exhaustion.

2 affected packages

libxpm, motif

Package 20.04 LTS
libxpm Needs evaluation
motif Needs evaluation
Show less packages

CVE-2026-94286

Medium priority
Needs evaluation

An out-of-bounds read in libXtst's RECORD reply parser in libXtst before 1.2.6 could be used by malicious X servers to crash attached X clients.

1 affected package

libxtst

Package 20.04 LTS
libxtst Needs evaluation
Show less packages

CVE-2026-94285

Medium priority
Needs evaluation

An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.

1 affected package

libx11

Package 20.04 LTS
libx11 Needs evaluation
Show less packages

CVE-2026-94284

Medium priority
Needs evaluation

An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.

1 affected package

libx11

Package 20.04 LTS
libx11 Needs evaluation
Show less packages