Search CVE reports


Toggle filters

191 – 200 of 53310 results

Status is adjusted based on your filters.


CVE-2026-87799

Medium priority

Not in release

Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes...

1 affected package

lxd

Package 22.04 LTS
lxd Not in release
Show less packages

CVE-2026-87798

Medium priority

Not in release

Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.0.2 up to 6.9 (fixed in 4.0.14, 5.0.10 and 5.21.8) on Linux allows an attacker with root access inside a virtual machine...

1 affected package

lxd

Package 22.04 LTS
lxd Not in release
Show less packages

CVE-2026-86335

Medium priority

Not in release

Missing Authorization in imageDownload in Canonical LXD before 5.0.10, 5.21.8, and 6.10 on Linux allows a project-restricted client to access private images from other projects via local fingerprint reuse during image or instance...

1 affected package

lxd

Package 22.04 LTS
lxd Not in release
Show less packages

CVE-2026-86334

Medium priority

Not in release

Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms allows a remote malicious or machine-in-the-middle image server to overwrite...

1 affected package

lxd

Package 22.04 LTS
lxd Not in release
Show less packages

CVE-2026-85644

Medium priority
Needs evaluation

XS::Parse::Infix versions from 0.40 through 0.49 for Perl treat a number as an array reference. The wrapper function XS::Parse::Infix generates for a list-associative infix operator checks whether arguments are array references,...

1 affected package

libxs-parse-keyword-perl

Package 22.04 LTS
libxs-parse-keyword-perl Needs evaluation
Show less packages

CVE-2026-85526

Medium priority

Not in release

Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root...

2 affected packages

incus, lxd

Package 22.04 LTS
incus Not in release
lxd Not in release
Show less packages

CVE-2026-85185

Medium priority

Not in release

Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete...

2 affected packages

incus, lxd

Package 22.04 LTS
incus Not in release
lxd Not in release
Show less packages

CVE-2026-84784

Low priority
Vulnerable

QUIC: Unbounded RETIRE_CONNECTION_ID Backlog

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 22.04 LTS
openssl Not affected
openssl-fips Not affected
openssl1.0 Not in release
nodejs Vulnerable
edk2 Not affected
edk2-hwe Not in release
Show less packages

CVE-2026-84783

Medium priority
Vulnerable

Use-After-Free in X.509 Extension Cache Under Concurrent Use

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 22.04 LTS
openssl Not affected
openssl-fips Not affected
openssl1.0 Not in release
nodejs Vulnerable
edk2 Not affected
edk2-hwe Not in release
Show less packages

CVE-2026-84782

High priority

Some fixes available 1 of 3

DTLS Retransmits Handshake Messages From a Stale Buffer Offset

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 22.04 LTS
openssl Fixed
openssl-fips Not in release
openssl1.0 Not in release
nodejs Vulnerable
edk2 Needs evaluation
edk2-hwe Not in release
Show less packages