Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Canonical — Vulnerabilities & Security Advisories 155

Browse all 155 CVE security advisories affecting Canonical. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Canonical Ltd. primarily develops and maintains Ubuntu, a widely deployed Linux distribution, alongside the OpenStack cloud infrastructure platform and the Snap package management system. Security audits reveal a significant volume of recorded vulnerabilities, currently totaling 107 CVEs, reflecting the extensive codebase and third-party dependencies inherent in these large-scale software ecosystems. Historically, the most prevalent vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from improper input validation or insecure default configurations within associated services. While no single catastrophic incident has defined the company’s security history, the sheer number of disclosed issues highlights the challenges of maintaining rigorous patch cycles across diverse components. These findings underscore the necessity for continuous monitoring and timely updates for organizations relying on Canonical’s open-source technologies to mitigate potential exploitation risks.

CVE ID Title CVSS Severity Published
CVE-2024-1724 snapd allows $HOME/bin symlink — snap CWE-732 6.3 Medium 2024-07-25
CVE-2024-41129 The ops library leaks secrets if `subprocess.CalledProcessError` happens with a `secret-*` CLI command — operator CWE-532 4.4 Medium 2024-07-22
CVE-2023-5536 LXD 安全漏洞 — Ubuntu Server 5.0 Medium 2023-12-12
CVE-2023-32629 Canonical Ubuntu 安全漏洞 — Ubuntu Kernel CWE-863 7.8 High 2023-07-26
CVE-2023-2640 Canonical Ubuntu Linux 安全漏洞 — Ubuntu Kernel CWE-863 7.8 High 2023-07-26
CVE-2021-3747 MacOS version of Multipass incorrect owner for application directory — Multipass CWE-732 8.8 High 2021-10-01
CVE-2021-3710 Apport info disclosure via path traversal bug in read_file — apport CWE-24 6.5 Medium 2021-10-01
CVE-2021-3709 Apport file permission bypass through emacs byte compilation errors — apport CWE-538 6.5 Medium 2021-10-01
CVE-2021-3626 Windows version of Multipass unauthenticated localhost tcp control socket can perform mounts — Multipass CWE-73 8.8 High 2021-10-01
CVE-2021-32556 apport get_modified_conffiles() function command injection — apport CWE-78 3.8 Low 2021-06-12
CVE-2021-32557 apport process_report() arbitrary file write — apport CWE-59 5.2 Medium 2021-06-12
CVE-2021-32555 apport read_file() function could follow maliciously constructed symbolic links — apport CWE-59 7.3 High 2021-06-12
CVE-2021-32553 apport read_file() function could follow maliciously constructed symbolic links — apport CWE-59 7.3 High 2021-06-12
CVE-2021-32554 apport read_file() function could follow maliciously constructed symbolic links — apport CWE-59 7.3 High 2021-06-12
CVE-2021-32552 apport read_file() function could follow maliciously constructed symbolic links — apport CWE-59 7.3 High 2021-06-12
CVE-2021-32550 apport read_file() function could follow maliciously constructed symbolic links — apport CWE-59 7.3 High 2021-06-12
CVE-2021-32551 apport read_file() function could follow maliciously constructed symbolic links — apport CWE-59 7.3 High 2021-06-12
CVE-2021-32549 apport read_file() function could follow maliciously constructed symbolic links — apport CWE-59 7.3 High 2021-06-12
CVE-2021-32548 apport read_file() function could follow maliciously constructed symbolic links — apport CWE-59 7.3 High 2021-06-12
CVE-2021-32547 apport read_file() function could follow maliciously constructed symbolic links — apport CWE-59 7.3 High 2021-06-12
CVE-2021-25684 apport can be stalled by reading a FIFO — apport CWE-20 8.8 High 2021-06-11
CVE-2021-25683 apport improperly parses /proc/pid/stat — apport CWE-20 8.8 High 2021-06-11
CVE-2021-25682 apport improperly parses /proc/pid/status — apport CWE-20 8.8 High 2021-06-11
CVE-2013-1055 Potential DoS through abuse of rate limit in libunity-webapps for Firefox — unity-firefox-extension CWE-404 4.3 Medium 2021-04-07
CVE-2013-1054 Possible remote DOS in WebApps — unity-firefox-extension CWE-404 4.3 Medium 2021-04-07
CVE-2020-16119 DCCP CCID structure use-after-free — Linux kernel CWE-416 6.3 Medium 2021-01-14
CVE-2013-1053 Insecure crypto for storing passwords — remote-login-service CWE-261 5.5 Medium 2021-01-13
CVE-2020-27351 Various memory and file descriptor leaks in apt-python — python-apt CWE-772 2.0 Low 2020-12-10
CVE-2020-27350 apt integer wraparound — apt CWE-190 5.7 Medium 2020-12-10
CVE-2020-16128 Aptdaemon error messages disclosed file existence to unprivileged users via dbus properties — aptdaemon CWE-209 3.8 Low 2020-12-09

This page lists every published CVE security advisory associated with Canonical. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.