Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
It was discovered that the get_starttime() function in data/apport did not properly parse the /proc/pid/stat file from the kernel. |
It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel. |
2Canonical Linux2Linux Kernel Ubuntu LinuxJun 17, 2026 Jun 4, 2021 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 The io_uring subsystem in the Linux kernel allowed the MAX_RW_COUNT limit to be bypassed in the PROVIDE_BUFFERS operation, which led to negative values being usedin mem_rw when reading /proc/<PID>/mem. This could be used...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxJun 17, 2026 Jun 4, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The eBPF ALU32 bounds tracking for bitwise ops (AND, OR and XOR) in the Linux kernel did not properly update 32-bit bounds, which could be turned into out of bounds reads and writes in the Linux kernel and therefore, arb...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxJun 17, 2026 Jun 4, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The eBPF RINGBUF bpf_ringbuf_reserve() function in the Linux kernel did not check that the allocated size was smaller than the ringbuf size, allowing an attacker to perform out-of-bounds writes within the kernel and ther...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraOpenvpn+1 moreJun 17, 2026 Apr 26, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further i...Show more |
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged us...Show more |
Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correctly. These could lead to either a double-free situation or memory not...Show more |
1Canonical 2Ubuntu Linux Unity Firefox ExtensionNov 21, 2024 Apr 7, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The unity-firefox-extension package could be tricked into dropping a C callback which was still in use, which Firefox would then free, causing Firefox to crash. This could be achieved by adding an action to the launcher...Show more |
1Canonical 2Ubuntu Linux Unity Firefox ExtensionNov 21, 2024 Apr 7, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The unity-firefox-extension package could be tricked into destroying the Unity webapps context, causing Firefox to crash. This could be achieved by spinning the event loop inside the webapps initialization callback. Fixe...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxJun 17, 2026 Mar 23, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source register was known to be 0. A local attacker with the ability to load bpf programs could use this gain ou...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLinux Kernel+1 moreJun 17, 2026 Mar 20, 2021 N/A· v4 6.0 MEDIUM· v3 3.6 LOW· v2 An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c has an off-by-one error (with a resultant integer underflow) affecting out-of-bounds speculation on pointer arithmetic, leading to side-cha...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLinux Kernel+1 moreJun 17, 2026 Mar 20, 2021 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and o...Show more |
5Canonical DebianLinux+2 more5Debian Linux Linux KernelSolidfire Baseboard Management Controller Firmware+2 moreJun 17, 2026 Mar 7, 2021 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages. |
2Canonical Linux2Linux Kernel Ubuntu LinuxJun 17, 2026 Feb 10, 2021 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 Overlayfs did not properly perform permission checking when copying up files in an overlayfs and could be exploited from within a user namespace, if, for example, unprivileged user namespaces were allowed. It was possibl...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxJun 17, 2026 Jan 14, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Use-after-free vulnerability in the Linux kernel exploitable by a local attacker due to reuse of a DCCP socket with an attached dccps_hc_tx_ccid object as a listener after being released. Fixed in Ubuntu Linux kernel 5.4...Show more |
1Canonical 1Remote Login Service Nov 21, 2024 Jan 13, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In crypt.c of remote-login-service, the cryptographic algorithm used to cache usernames and passwords is insecure. An attacker could use this vulnerability to recover usernames and passwords from the file. This issue aff...Show more |
3Canonical FedoraprojectGnome3Fedora Gdk PixbufUbuntu LinuxJun 17, 2026 Dec 26, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write_indexes. if c->self_code equals 10, self->code_table[10].extends will assign the value 11 to c. The...Show more |
Aptdaemon performed policykit checks after interacting with potentially untrusted files with elevated privileges. This affected versions prior to 1.1.1+bzr982-0ubuntu34.1, 1.1.1+bzr982-0ubuntu32.3, 1.1.1+bzr982-0ubuntu19...Show more |
The aptdaemon DBus interface disclosed file existence disclosure by setting Terminal/DebconfSocket properties, aka GHSL-2020-192 and GHSL-2020-196. This affected versions prior to 1.1.1+bzr982-0ubuntu34.1, 1.1.1+bzr982-0...Show more |