Canonical ubuntu-advantage-tools是英国Canonical公司的一款系统管理工具套件。 Canonical ubuntu-advantage-tools 37.3之前版本存在后置链接漏洞,该漏洞源于pro collect-logs命令框架中存在不安全的符号链接跟随问题,工具在收集诊断信息时使用可预测的临时文件路径或用户可访问的日志目录,而未验证文件类型或所有权,导致低权限的本地攻击者可通过在可预测目标路径创建指向任意root可读文件的符号链接,当root管理员执行pro co
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Canonical | Ubuntu 16.04 LTS | 37.1ubuntu0~16.04.1 | unaffected |
| Canonical | Ubuntu 18.04 LTS | 37.1ubuntu0~18.04.1 | unaffected |
| Canonical | Ubuntu 20.04 LTS | 37.1ubuntu0~20.04.1 | unaffected |
| Canonical | Ubuntu 22.04 LTS | 37.2ubuntu~22.04.1 | unaffected |
| Canonical | Ubuntu 24.04 LTS | 37.2ubuntu~24.04.1 | unaffected |
| Canonical | Ubuntu 26.04 LTS | 37.2ubuntu0.1 | unaffected |
| Canonical | ubuntu-pro-client (ubuntu-advantage-tools) | < 37.3 | affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Canonical | ubuntu-pro-client (ubuntu-advantage-tools) | 0 ~ 37.3 | - | |
| Canonical | Ubuntu 26.04 LTS | 37.2ubuntu0.1 | - | |
| Canonical | Ubuntu 24.04 LTS | 37.2ubuntu~24.04.1 | - | |
| Canonical | Ubuntu 22.04 LTS | 37.2ubuntu~22.04.1 | - | |
| Canonical | Ubuntu 20.04 LTS | 37.1ubuntu0~20.04.1 | - | |
| Canonical | Ubuntu 18.04 LTS | 37.1ubuntu0~18.04.1 | - | |
| Canonical | Ubuntu 16.04 LTS | 37.1ubuntu0~16.04.1 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-11386 | 9.0 CRITICAL | ubuntu-pro-client Input Validation Vulnerability Leading to Arbitrary APT Directive Inject |
| CVE-2026-9494 | 5.5 MEDIUM | ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure in Process Co |
No comments yet