Search CVE reports
1 – 10 of 33257 results
A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within...
1 affected package
libvirt
| Package | 26.04 LTS |
|---|---|
| libvirt | Needs evaluation |
Not in release
An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level...
1 affected package
lxd
| Package | 26.04 LTS |
|---|---|
| lxd | Not in release |
Not in release
An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource limits during volume operations:...
1 affected package
lxd
| Package | 26.04 LTS |
|---|---|
| lxd | Not in release |
Not in release
An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance...
1 affected package
lxd
| Package | 26.04 LTS |
|---|---|
| lxd | Not in release |
Not in release
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides...
1 affected package
lxd
| Package | 26.04 LTS |
|---|---|
| lxd | Not in release |
Not in release
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions. When a project is configured with restrictions on container privileges (such as enforcing...
1 affected package
lxd
| Package | 26.04 LTS |
|---|---|
| lxd | Not in release |
Not in release
A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and confine the...
1 affected package
lxd
| Package | 26.04 LTS |
|---|---|
| lxd | Not in release |
Not in release
A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate whether the metadata.yaml file is...
1 affected package
lxd
| Package | 26.04 LTS |
|---|---|
| lxd | Not in release |
Not in release
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster...
1 affected package
lxd
| Package | 26.04 LTS |
|---|---|
| lxd | Not in release |
security update
1 affected package
libheif
| Package | 26.04 LTS |
|---|---|
| libheif | Needs evaluation |