Search CVE reports


Toggle filters

1 – 10 of 33257 results

Status is adjusted based on your filters.


CVE-2026-63622

Medium priority
Needs evaluation

A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within...

1 affected package

libvirt

Package 26.04 LTS
libvirt Needs evaluation
Show less packages

CVE-2026-63300

Medium priority

Not in release

An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level...

1 affected package

lxd

Package 26.04 LTS
lxd Not in release
Show less packages

CVE-2026-63299

Medium priority

Not in release

An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource limits during volume operations:...

1 affected package

lxd

Package 26.04 LTS
lxd Not in release
Show less packages

CVE-2026-63297

Medium priority

Not in release

An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance...

1 affected package

lxd

Package 26.04 LTS
lxd Not in release
Show less packages

CVE-2026-63296

Medium priority

Not in release

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides...

1 affected package

lxd

Package 26.04 LTS
lxd Not in release
Show less packages

CVE-2026-63295

Medium priority

Not in release

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions. When a project is configured with restrictions on container privileges (such as enforcing...

1 affected package

lxd

Package 26.04 LTS
lxd Not in release
Show less packages

CVE-2026-63294

Medium priority

Not in release

A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and confine the...

1 affected package

lxd

Package 26.04 LTS
lxd Not in release
Show less packages

CVE-2026-63293

Medium priority

Not in release

A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate whether the metadata.yaml file is...

1 affected package

lxd

Package 26.04 LTS
lxd Not in release
Show less packages

CVE-2026-62420

Medium priority

Not in release

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster...

1 affected package

lxd

Package 26.04 LTS
lxd Not in release
Show less packages

CVE-2026-62292

Medium priority
Needs evaluation

security update

1 affected package

libheif

Package 26.04 LTS
libheif Needs evaluation
Show less packages