Canonical Multipass是Canonical开源的一个Ubuntu的虚拟实例。 Canonical Multipass 1.16.3之前版本存在安全漏洞,该漏洞源于sshfs_server组件中validate_path函数存在路径包含绕过问题,仅执行字符串前缀比较而未进行路径分隔符验证或..规范化,可能导致具有root权限的本地攻击者通过procfs向sshfs_server进程stdin/stdout管道注入原始SFTP帧,强制主机端root进程解析遍历并打开指定挂载边界之外的文件,导致
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-49237 | 7.8 HIGH | Local Privilege Escalation in Canonical Multipass |
| CVE-2026-47331 | 7.8 HIGH | Use-after-free in Ubuntu Linux AppArmor notification handling |
| CVE-2026-47333 | 7.8 HIGH | Out-of-bounds read in Ubuntu Linux AppArmor notification handling |
| CVE-2026-47328 | 6.1 MEDIUM | Invalid pointer deallocation in Ubuntu Linux AppArmor notification handling |
| CVE-2026-47332 | 5.5 MEDIUM | Out-of-bounds read in Ubuntu Linux AppArmor notification handling |
| CVE-2026-47334 | 5.5 MEDIUM | Deadlock or kernel panic in Ubuntu Linux AppArmor notification handling |
| CVE-2026-47326 | 5.5 MEDIUM | Memory leak in Ubuntu Linux AppArmor large notification response allocation |
| CVE-2026-47335 | 5.5 MEDIUM | NULL pointer dereference in Ubuntu Linux AppArmor notification handling |
| CVE-2026-47336 | 3.3 LOW | Use of uninitialized value in Ubuntu Linux AppArmor IPv4/IPv6 socket mediation rules |
| CVE-2026-47327 | 3.3 LOW | NULL pointer dereference in Ubuntu Linux AppArmor notification handling |
| CVE-2026-47337 | 3.3 LOW | NULL pointer dereference in Ubuntu Linux AppArmor IPv4/IPv6 socket mediation |
| CVE-2026-47330 | 3.3 LOW | Use of uninitialized value in Ubuntu Linux AppArmor notification handling |
| CVE-2026-47329 | 3.3 LOW | Incorrect validation of field size in Ubuntu Linux AppArmor notification responses |
No comments yet