Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Canonical — Vulnerabilities & Security Advisories 153

Browse all 153 CVE security advisories affecting Canonical. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Canonical Ltd. primarily develops and maintains Ubuntu, a widely deployed Linux distribution, alongside the OpenStack cloud infrastructure platform and the Snap package management system. Security audits reveal a significant volume of recorded vulnerabilities, currently totaling 107 CVEs, reflecting the extensive codebase and third-party dependencies inherent in these large-scale software ecosystems. Historically, the most prevalent vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from improper input validation or insecure default configurations within associated services. While no single catastrophic incident has defined the company’s security history, the sheer number of disclosed issues highlights the challenges of maintaining rigorous patch cycles across diverse components. These findings underscore the necessity for continuous monitoring and timely updates for organizations relying on Canonical’s open-source technologies to mitigate potential exploitation risks.

CVE ID Title CVSS Severity Published
CVE-2026-102371 wsl-pro-service: Ubuntu Pro token exposed via process command-line arguments — Ubuntu Pro for WSL CWE-214 5.7 Medium 2026-09-29
CVE-2026-87798 LXD client recursive file pull allows directory escape via malicious VM agent — LXD CWE-59 5.8 Medium 2026-09-28
CVE-2026-87799 Arbitrary file write on LXD host via symlink in migration stream — LXD CWE-59 9.9 Critical 2026-09-28
CVE-2026-97335 Incorrect authorization in LXD storage volume API allows reading volumes from other projects — LXD CWE-863 7.7 High 2026-09-28
CVE-2026-85185 Path traversal in LXD btrfs storage driver allows arbitrary file deletion and write on host as root — LXD CWE-22 9.6 Critical 2026-09-28
CVE-2026-85526 Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipulation in LXD — LXD CWE-22 9.9 Critical 2026-09-28
CVE-2026-86335 LXD Cross-Project Private Image Theft via Unsanitized GetImageFromAnyProject Local Reuse — LXD CWE-862 6.3 Medium 2026-09-28
CVE-2026-86334 CLI Path Traversal via Content-Disposition in LXD Image Export/Copy — LXD CWE-22 4.2 Medium 2026-09-28
CVE-2026-66897 Instance template path traversal allows arbitrary host file write as root — LXD CWE-22 9.9 Critical 2026-08-24
CVE-2026-77113 Path Traversal Vulnerability in apport-unpack — Apport CWE-23 6.7 Medium 2026-08-20
CVE-2026-61898 accountsservice: shell injection via attacker-controlled ~/.pam_environment in Ubuntu language helper scripts — accountsservice CWE-78 7.8 High 2026-08-20
CVE-2026-61897 accountsservice: incomplete privilege drop when running Ubuntu-specific language helper scripts — accountsservice CWE-273 7.8 High 2026-08-20
CVE-2026-16033 Arbitrary file read+write on host via templates/ symlink in malicious image — LXD CWE-22 8.5 High 2026-08-12
CVE-2026-66898 Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE — LXD CWE-22 9.9 Critical 2026-08-12
CVE-2026-63293 Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root — LXD CWE-59 9.9 Critical 2026-08-12
CVE-2026-63294 Root RCE via image backup.yaml symlink — LXD CWE-59 9.9 Critical 2026-08-12
CVE-2026-63295 Project restriction `restricted.containers.privilege=isolated` bypassable by omitting `security.idmap.isolated` — LXD CWE-863 4.3 Medium 2026-08-12
CVE-2026-63296 Project restriction bypass via instance migration config override — LXD CWE-863 9.9 Critical 2026-08-12
CVE-2026-63297 Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge — LXD CWE-367 9.9 Critical 2026-08-12
CVE-2026-63298 LXD arbitrary lxc.conf directive injection via NVIDIA instance configuration — LXD CWE-78 8.7 Critical 2026-08-12
CVE-2026-63299 Storage volume cross-project move and snapshot restore bypass project disk limits — LXD CWE-770 8.5 Critical 2026-08-12
CVE-2026-62420 Cross-project cluster migration bypasses project restrictions via cluster notification flag — LXD CWE-863 9.9 Critical 2026-08-12
CVE-2026-63300 Cross-project instance move bypasses all project restrictions allowing host command execution — LXD CWE-862 9.9 Critical 2026-08-12
CVE-2026-12391 ubuntu-pro-client Local Privilege Escalation and Information Disclosure via Symlink Arbitrary File Read in collect-logs — ubuntu-pro-client (ubuntu-advantage-tools) CWE-59 5.0 Medium 2026-07-16
CVE-2026-11386 ubuntu-pro-client Input Validation Vulnerability Leading to Arbitrary APT Directive Injection and Remote Code Execution — ubuntu-pro-client (ubuntu-advantage-tools) CWE-20 9.0 Critical 2026-07-16
CVE-2026-9494 ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure in Process Command Line — ubuntu-pro-client (ubuntu-advantage-tools) CWE-214 5.5 Medium 2026-07-16
CVE-2026-10037 Sandbox Escape in Ubuntu OpenJDK Packages via xdg-desktop-portal — Ubuntu CWE-20 8.8 High 2026-07-08
CVE-2026-28385 SSRF via image import from URL allows internal network probing by authenticated users — lxd CWE-918 5.0 Medium 2026-06-26
CVE-2026-9640 LXD Snapshot Import Privilege Escalation Vulnerability — LXD CWE-863 7.2 High 2026-06-26
CVE-2026-9639 Authenticated Denial of Service via Malicious Backup Tarball in LXD — LXD CWE-476 6.5 Medium 2026-06-26

This page lists every published CVE security advisory associated with Canonical. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.