← Back

Canonical

canonical

4,238 CVEs • 60 products

Products (60)

Click to collapse
Toggle
Lxd
lxd
Juju
juju
Apport
apport
Snapd
snapd
Cloud Init
cloud-init
Multipass
multipass
Ubuntu Core
ubuntu_core
Ubuntu Touch
ubuntu_touch
Maas
maas
Subiquity
subiquity
Landscape
landscape
Authd
authd
Acpi Support
acpi-support
Ubuntu
ubuntu
Lxcfs
lxcfs
Spread
spread
Php5
php5
Telepathy Idle
telepathy-idle
Libpam Modules
libpam-modules
Reportbug
reportbug
Ubuntu Image
ubuntu-image
Bazaar
bazaar
Selinux
selinux
Apparmor
apparmor
Ubuntu Cobbler
ubuntu_cobbler
Microk8s
microk8s
C Kernel
c-kernel
Whoopsie
whoopsie
Checkinstall
checkinstall
Ppp
ppp
Snapcraft
snapcraft
Pebble
pebble
Netplan
netplan
Anbox Cloud
anbox_cloud
Juju/utils
juju/utils
Pdfunite
pdfunite

CVEs (4,238)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
13Almalinux
AmazonApple+10 more
53500f Firmware
8300 Firmware8700 Firmware+50 more
Jun 17, 2026
Jul 1, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able t...Show more
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.Show less
1Canonical
1Ubuntu Advantage Desktop Daemon
Jun 17, 2026
Jun 27, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext.
1Canonical
2Snapd
Ubuntu Linux
Jun 17, 2026
Jun 21, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd will move processes from the containers created and managed by these snap...Show more
When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd will move processes from the containers created and managed by these snaps into the cgroup of the main daemon within the snap itself when reloading system units. This may grant additional privileges to a container within the snap that were not originally intended.Show less
1Canonical
1Netplan
Jun 17, 2026
Jun 7, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
netplan leaks the private key of wireguard to local users. Versions after 1.0 are not affected.
2Apport Project
Canonical
2Apport
Ubuntu Linux
Jun 17, 2026
Jun 4, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing
2Apport Project
Canonical
2Apport
Ubuntu Linux
Jun 17, 2026
Jun 4, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Apport does not disable python crash handler before entering chroot
2Apport Project
Canonical
2Apport
Ubuntu Linux
Jun 17, 2026
Jun 4, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
is_closing_session() allows users to consume RAM in the Apport process
2Apport Project
Canonical
2Apport
Ubuntu Linux
Jun 17, 2026
Jun 4, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
is_closing_session() allows users to create arbitrary tcp dbus connections
2Apport Project
Canonical
2Apport
Ubuntu Linux
Jun 17, 2026
Jun 4, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
is_closing_session() allows users to fill up apport.log
2Apport Project
Canonical
2Apport
Ubuntu Linux
Jun 17, 2026
Jun 4, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
~/.config/apport/settings parsing is vulnerable to "billion laughs" attack
1Canonical
2Apport
Ubuntu Linux
Jun 17, 2026
Jun 3, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Apport can be tricked into connecting to arbitrary sockets as the root user
1Canonical
1Subiquity
Jun 17, 2026
Jun 3, 2024
N/A· v4
8.4 HIGH· v3
N/A· v2
Subiquity Shows Guided Storage Passphrase in Plaintext with Read-all Permissions
1Canonical
2Apport
Ubuntu Linux
Jun 17, 2026
Jun 3, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary code as root.
1Canonical
1Snapd
Jun 17, 2026
May 31, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. It was found that snapctl did not properly parse command-line argument...Show more
The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. It was found that snapctl did not properly parse command-line arguments, allowing an unprivileged user to trigger an authorised action on behalf of the snap that would normally require administrator privileges to perform. This could possibly allow an unprivileged user to perform a denial of service or similar.Show less
1Canonical
1Pebble
Jun 17, 2026
Apr 4, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
It was discovered that Canonical's Pebble service manager read-file API and the associated pebble pull command, before v1.10.2, allowed unprivileged local users to read files with root-equivalent permissions when Pebble...Show more
It was discovered that Canonical's Pebble service manager read-file API and the associated pebble pull command, before v1.10.2, allowed unprivileged local users to read files with root-equivalent permissions when Pebble was running as root. Fixes are also available as backports to v1.1.1, v1.4.2, and v1.7.4.Show less
2Canonical
Tianocore
2Edk2
Lxd
Jun 17, 2026
Feb 14, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.
3Canonical
DebianTianocore
3Debian Linux
Edk2Lxd
Jun 17, 2026
Feb 14, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.
1Canonical
1Ubuntu Pipewire Pulse
Jun 17, 2026
Jan 24, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Ubuntu's pipewire-pulse in snap grants microphone access even when the snap interface for audio-record is not set.
2Canonical
Linux
2Linux Kernel
Ubuntu Linux
Jun 17, 2026
Jan 8, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
The Linux kernel io_uring IORING_OP_SOCKET operation contained a double free in function __sys_socket_file() in file net/socket.c. This issue was introduced in da214a475f8bd1d3e9e7a19ddfeb4d1617551bab and fixed in 649c15...Show more
The Linux kernel io_uring IORING_OP_SOCKET operation contained a double free in function __sys_socket_file() in file net/socket.c. This issue was introduced in da214a475f8bd1d3e9e7a19ddfeb4d1617551bab and fixed in 649c15c7691e9b13cbe9bf6c65c365350e056067.Show less
4Canonical
FedoraprojectLinux+1 more
4Enterprise Linux
FedoraLinux Kernel+1 more
Jun 17, 2026
Jan 8, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local attacker could use this to possibly execut...Show more
It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local attacker could use this to possibly execute arbitrary code.Show less