Vulnerabilidades em lxc

40 resultados
Análise Vexday

O LXC apresenta 22 vulnerabilidades catalogadas, com 10 divulgadas nos últimos 90 dias, indicando evolução recente do risco. Não há evidências de exploração ativa em circulação, mas 2 vulnerabilidades críticas e a predominância de dereferenciais nulos (CWE-476) demandam atenção imediata na atualização de versões.

CVE-2026-48749CRITICALIncus has an arbitrary file read+write on host via rootfs/ symlink in malicious imageEPSS 0.8%CVE-2026-48752CRITICALIncus has arbitrary file read+write on host via templates/ symlink in malicious imageEPSS 0.8%CVE-2026-48750CRITICALIncus has an arbitrary file write on host via `exec-output` symlink in crafted imageEPSS 0.8%CVE-2026-23954HIGHIncus container image templating arbitrary host file read and writeEPSS 0.8%CVE-2026-48753CRITICALIncus has an arbitrary file write via path traversal in S3 multipart uploadEPSS 0.7%CVE-2026-48751CRITICALIncus has a restricted project bypass leading to arbitrary command executionEPSS 0.7%CVE-2026-23953HIGHIncus container environment configuration newline injectionEPSS 0.5%CVE-2026-33897CRITICALIncus vulnerable to arbitrary file read and write through pongo templatesEPSS 0.5%CVE-2026-33945CRITICALAbitrary file write through systemd-creds optionEPSS 0.4%CVE-2026-48769CRITICALIncus has an arbitrary file write on its client due to trusted image hashEPSS 0.4%CVE-2026-48755CRITICALIncus has an argument injection in backup compression algorithm leading to AFW and ACEEPSS 0.4%CVE-2026-63125CRITICALIncus vulnerable to root RCE via image backup.yaml symlinkEPSS 0.4%CVE-2026-41684MEDIUMIncus: Nil Dereferences on Restore via Malformed YAMLEPSS 0.4%CVE-2026-40251HIGHIncus out-of-bounds panic in snapshot metadata handling allows denial of serviceEPSS 0.4%CVE-2026-40195HIGHIncus nil-pointer dereference in storage bucket import allows denial of serviceEPSS 0.4%CVE-2026-41647MEDIUMIncus: Nil-Pointer Dereference via S3 Bucket ImportEPSS 0.4%CVE-2026-33743MEDIUMIncus vulnerable to denial of source through crafted bucket backup fileEPSS 0.4%CVE-2026-40197HIGHIncus nil-pointer dereference in custom volume import allows denial of serviceEPSS 0.4%CVE-2026-33711MEDIUMIncus vulnerable to local privilege escalation through VM screenshot pathEPSS 0.4%CVE-2026-33898HIGHLocal Incus UI web server vulnerable to nuthentication bypassEPSS 0.3%