VYPR

Vendor CVEs

Lxc

All CVEs

56 total · sorted by risk
  • CVE-2019-5736HigFeb 11, 2019
    risk 0.60cvss 8.6epss 0.98

    runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new…

  • CVE-2016-8649CriMay 1, 2017
    risk 0.59cvss 9.1epss 0.03

    lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inherited file descriptor, of the host's /proc, to access the rest of the host's filesystem via the openat() family of syscalls.

  • CVE-2026-63343CriAug 21, 2026
    risk 0.57cvss 9.9epss 0.00

    Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an authenticated Incus user to read or overwrite any file on the host as root via the instance…

  • CVE-2026-63125CriAug 21, 2026
    risk 0.57cvss 9.9epss 0.01

    Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and `can_create_instances`) can execute arbitrary code as root on the host. A crafted image ships…

  • CVE-2026-62941CriAug 21, 2026
    risk 0.57cvss 9.9epss 0.00

    Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCreation`) runs BEFORE the source instance's configuration is merged into the request. Dangerous configuration…

  • CVE-2026-62940CriAug 21, 2026
    risk 0.57cvss 9.9epss 0.00

    Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluster member, user-supplied configuration overrides (including security-critical keys like `security.privileged` and `raw.lxc`) are applied without any…

  • CVE-2026-62867CriAug 21, 2026
    risk 0.57cvss 9.9epss 0.01

    Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration leads to argument injection in the constructed filesystem creation command line. This allows a…

  • CVE-2026-48769CriAug 21, 2026
    risk 0.57cvss 9.9epss 0.01

    Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary command execution as root on the server.…

  • CVE-2026-48755CriAug 21, 2026
    risk 0.57cvss 9.9epss 0.01

    Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary file write on the host, possibly leading to…

  • CVE-2026-48753CriAug 21, 2026
    risk 0.57cvss 9.9epss 0.01

    Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution. Version 7.1.0 fixes the…

  • CVE-2026-48752CriAug 21, 2026
    risk 0.57cvss 9.9epss 0.01

    Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 patches the issue.

  • CVE-2026-48751CriAug 21, 2026
    risk 0.57cvss 9.9epss 0.01

    Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on the Incus server by abusing lowlevel hooks such as `raw.lxc` and `raw.qemu`.…

  • CVE-2026-48750CriAug 21, 2026
    risk 0.57cvss 9.9epss 0.01

    Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the instance. If `exec-output` is a symlink, file named…

  • CVE-2026-48749CriAug 21, 2026
    risk 0.57cvss 9.9epss 0.01

    Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 fixes the issue.

  • CVE-2026-33945CriMar 27, 2026
    risk 0.57cvss 9.9epss 0.01

    Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to systemd in the guest. For containers, this is handled through a shared directory. Prior to version 6.23.0, an attacker can set a configuration key named something…

  • CVE-2026-33897CriMar 26, 2026
    risk 0.57cvss 9.9epss 0.01

    Incus is a system container and virtual machine manager. Prior to version 6.23.0, instance template files can be used to cause arbitrary read or writes as root on the host server. Incus allows for pongo2 templates within instances which can be used at various times in the…

  • CVE-2026-23954HigJan 22, 2026
    risk 0.57cvss 8.7epss 0.01

    Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom image (e.g a member of the ‘incus’ group) to use directory traversal or symbolic links in the templating functionality to…

  • CVE-2026-23953HigJan 22, 2026
    risk 0.57cvss 8.7epss 0.01

    Incus is a system container and virtual machine manager. In versions 6.20.0 and below, a user with the ability to launch a container with a custom YAML configuration (e.g a member of the ‘incus’ group) can create an environment variable containing newlines, which can be used…

  • CVE-2017-18641HigFeb 10, 2020
    risk 0.53cvss 8.1epss 0.01

    In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap containers.

  • CVE-2026-33898HigMar 27, 2026
    risk 0.50cvss 8.8epss 0.00

    Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui` incorrectly validates the authentication token such that an invalid value will be accepted. `incus webui` runs a local web server on a random localhost port.…

  • CVE-2016-10124HigJan 9, 2017
    risk 0.49cvss 8.6epss 0.02

    An issue was discovered in Linux Containers (LXC) before 2016-02-22. When executing a program via lxc-attach, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the…

  • CVE-2025-52890HigJun 25, 2025
    risk 0.46cvss 8.1epss 0.00

    Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus versions 6.12 and 6.13generates nftables rules that partially bypass security options `security.mac_filtering`, `security.ipv4_filtering` and…

  • CVE-2026-33711HigMar 26, 2026
    risk 0.44cvss 7.8epss 0.00

    Incus is a system container and virtual machine manager. Incus provides an API to retrieve VM screenshots. That API relies on the use of a temporary file for QEMU to write the screenshot to which is then picked up and sent to the user prior to deletion. As versions prior to…

  • CVE-2025-64507HigNov 10, 2025
    risk 0.44cvss 7.8epss 0.00

    Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.19.0 affects any Incus user in an environment where an unprivileged user may have root access to a container with an attached custom storage volume that has the `security.shifted`…

  • CVE-2026-55622HigAug 21, 2026
    risk 0.43cvss 7.7epss 0.00

    Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name of an instance in that project can copy the…

  • CVE-2026-55621HigAug 21, 2026
    risk 0.43cvss 7.7epss 0.00

    Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for custom volume copying where an attacker knowing the name of a project that they don't have access to and the name of a custom volume in that project can copy…

  • CVE-2026-32606HigMar 18, 2026
    risk 0.42cvss 7.6epss 0.00

    IncusOS is an immutable OS image dedicated to running Incus. Prior to 202603142010, the default configuration of systemd-cryptenroll as used by IncusOS through mkosi allows for an attacker with physical access to the machine to access the encrypted data without requiring any…

  • CVE-2026-52727HigSep 17, 2026
    risk 0.40cvss 7.2epss 0.01

    lxc-ci contains continuous integration and image-build scripts for LXC. Prior to the 2026-05-28 Arch Linux image publication, images built from images/archlinux.yaml retain the same pacman local-signing private key in /etc/pacman.d/gnupg and redistribute it to every container or…

  • CVE-2015-1340HigApr 22, 2019
    risk 0.39cvss 7.0epss 0.01

    LXD before version 0.19-0ubuntu5 doUidshiftIntoContainer() has an unsafe Chmod() call that races against the stat in the Filepath.Walk() function. A symbolic link created in that window could cause any file on the system to have any mode of the attacker's choice.

  • CVE-2026-41684MedMay 7, 2026
    risk 0.35cvss 6.5epss 0.00

    Incus is a system container and virtual machine manager. Prior to version 7.0.0, backup.GetInfo() trusts the inline backup/index.yaml config when present and only falls back to parsing the legacy backup/container/backup.yaml file if result.Config == nil. As a result, an archive…

  • CVE-2026-41647MedMay 7, 2026
    risk 0.35cvss 6.5epss 0.00

    Incus is a system container and virtual machine manager. Prior to version 7.0.0, a missing error handling could lead an authenticated Incus user to cause a daemon crash through the import of a truncated storage bucket backup file. This issue has been patched in version 7.0.0.

  • CVE-2026-40251MedMay 6, 2026
    risk 0.35cvss 6.5epss 0.00

    Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows an authenticated user with access to the storage volume feature to cause the Incus daemon to crash. The backup restore subsystem…

  • CVE-2026-40197MedMay 6, 2026
    risk 0.35cvss 6.5epss 0.00

    Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows an authenticated user with access to the storage volume feature to cause the Incus daemon to crash. The custom volume backup…

  • CVE-2026-40195MedMay 6, 2026
    risk 0.35cvss 6.5epss 0.00

    Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage bucket import logic allows an authenticated user with access to the storage bucket feature to cause the Incus daemon to crash. The vulnerability is present…

  • CVE-2026-39402MedMay 5, 2026
    risk 0.35cvss 6.5epss 0.00

    lxc is a Linux container runtime. In the setuid helper lxc-user-nic, the delete path contains a logic flaw in the find_line() function that allows an unprivileged user to delete OVS-attached network interfaces belonging to other users. When lxc-user-nic delete scans its NIC…

  • CVE-2026-33743MedMar 26, 2026
    risk 0.35cvss 6.5epss 0.00

    Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket backup can be used by an user with access to Incus' storage bucket feature to crash the Incus daemon. Repeated use of this attack can be used to keep the server…

  • CVE-2026-41648MedMay 7, 2026
    risk 0.26cvss 5.0epss 0.00

    Incus is a system container and virtual machine manager. Prior to version 7.0.0, user provided image and backup tarballs would be unpacked and YAML files parsed without any size restrictions. This was making it easy for an authenticated user to provide a crafted image or backup…

  • CVE-2026-35527MedMay 5, 2026
    risk 0.26cvss 5.0epss 0.00

    Incus is an open source container and virtual machine manager. In versions prior to 7.0.0, the image import flow issues an outbound HEAD request to a user-supplied URL before validating the request against project restrictions such as restricted.images.servers. The…

  • CVE-2026-40243MedMay 6, 2026
    risk 0.24cvss 4.8epss 0.00

    Incus is a system container and virtual machine manager. In versions before 7.0.0, broken TLS validation logic in the OVN database connection logic can allow connections to an attacker's OVN database. The OVN client implementations disable Go standard TLS server verification and…

  • CVE-2026-33542MedMar 26, 2026
    risk 0.24cvss 4.8epss 0.00

    Incus is a system container and virtual machine manager. Prior to version 6.23.0, a lack of validation of the image fingerprint when downloading from simplestreams image servers opens the door to image cache poisoning and under very narrow circumstances exposes other tenants to…

  • CVE-2026-47753MedAug 21, 2026
    risk 0.22cvss —epss 0.00

    Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateInstanceFromBackup` in `internal/server/storage/backend.go` contains a nil-pointer dereference that an authenticated user with permission to create instances in any project can…

  • CVE-2022-47952LowJan 1, 2023
    risk 0.22cvss 3.3epss 0.01

    lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a protected directory tree, because "Failed to open" often indicates that a file does not exist, whereas "does not refer to a network namespace…

  • CVE-2026-62313MedAug 21, 2026
    risk 0.21cvss 4.3epss 0.00

    Incus is a system container and virtual machine manager. Prior to version 7.3.0, project-level enforcement of `restricted.containers.privilege=isolated` can be trivially bypassed, allowing a user to create a non-isolated (shared host idmap) container in a project that is…

  • CVE-2026-41685MedMay 7, 2026
    risk 0.21cvss 4.3epss 0.00

    Incus is a system container and virtual machine manager. Prior to version 7.0.0, uploads of large amount of data by authenticated users can run the Incus server out of disk space, potentially taking down the host system. The impact here is limited for anyone using…

  • CVE-2018-6556LowAug 10, 2018
    risk 0.21cvss 3.3epss 0.00

    lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise be able to reach. It may also be used to trigger side…

  • CVE-2017-5985LowMar 14, 2017
    risk 0.21cvss 3.3epss 0.00

    lxc-user-nic in Linux Containers (LXC) allows local users with a lxc-usernet allocation to create network interfaces on the host and choose the name of those interfaces by leveraging lack of netns ownership check.

  • CVE-2025-52889LowJun 25, 2025
    risk 0.15cvss 3.4epss 0.00

    Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus version 6.12 and 6.13 generates nftables rules for local services (DHCP, DNS...) that partially bypass security options `security.mac_filtering`,…

  • CVE-2026-48756LowAug 21, 2026
    risk 0.07cvss —epss 0.00

    Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateCustomVolumeFromBackup` in `internal/server/storage/backend.go` contains an unguarded `*time.Time` dereference on the `ExpiresAt` field of every volume-snapshot entry in an…

  • CVE-2026-48754LowAug 21, 2026
    risk 0.07cvss —epss 0.00

    Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).createDependentVolumesFromBackup` in `internal/server/storage/backend.go` contains a cluster of unguarded pointer derefs on every dependent-volume entry's `VolumeSnapshots[i]`, `Volume`,…

  • CVE-2015-1344Dec 7, 2015
    risk 0.00cvss —epss 0.00

    The do_write_pids function in lxcfs.c in LXCFS before 0.12 does not properly check permissions, which allows local users to gain privileges by writing a pid to the tasks file.

Page 1 of 2