Vulnerabilidades em lxc

40 resultados
Análise Vexday

O LXC apresenta 22 vulnerabilidades catalogadas, com 10 divulgadas nos últimos 90 dias, indicando evolução recente do risco. Não há evidências de exploração ativa em circulação, mas 2 vulnerabilidades críticas e a predominância de dereferenciais nulos (CWE-476) demandam atenção imediata na atualização de versões.

CVE-2026-41685MEDIUMIncus: Unbounded binary import disk exhaustionEPSS 0.3%CVE-2026-62867CRITICALIncus has an argument injection in storage volume block.create_options that leads to arbitrary command executionEPSS 0.3%CVE-2026-35527MEDIUMIncus blind SSRF via image import preflight HEAD requestEPSS 0.3%CVE-2026-41648MEDIUMIncus: Unbounded YAML Metadata Decode via ParsingEPSS 0.3%CVE-2026-63343CRITICALArbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as rootEPSS 0.3%CVE-2026-62941CRITICALIncus: Cross-project instance copy bypasses target project restrictions via TOCTOU in config mergeEPSS 0.2%CVE-2026-62940CRITICALIncus has a project restriction bypass via instance migration config overrideEPSS 0.2%CVE-2026-48756LOWIncus: CreateCustomVolumeFromBackup nil-pointer dereference on volume_snapshots[*].expires_at (sibling-field variant of GHSA-r7w7)EPSS 0.2%CVE-2026-48754LOWIncus: Nil-pointer dereference in createDependentVolumesFromBackup on disk.{Volume,VolumeSnapshots,Pool}EPSS 0.2%CVE-2026-62313MEDIUMIncus: Project restriction `restricted.containers.privilege=isolated` bypassable by omitting `security.idmap.isolated`EPSS 0.2%CVE-2025-52889LOWIncus vulnerable to DoS through antispoofing nftables firewall rule bypass on bridge networks with ACLsEPSS 0.2%CVE-2026-55622HIGHIncus has a project restriction bypass in instance copy across projectsEPSS 0.2%CVE-2026-55621HIGHIncus has a project restriction bypass for custom volume copy across projectsEPSS 0.2%CVE-2025-52890HIGHIncus vulnerable to antispoofing nftables firewall rule bypass on bridge networks with ACLsEPSS 0.2%CVE-2026-33542MEDIUMIncus does not verify combined fingerprint when downloading images from simplestreams serversEPSS 0.2%CVE-2026-40243LOWIncus OVN TLS verification accepts peer-supplied roots and permits endpoint impersonationEPSS 0.2%CVE-2025-64507HIGHIncus vulnerable to local privilege escalation through custom storage volumesEPSS 0.2%CVE-2026-39402MEDIUMlxc lxc-user-nic insufficient ownership validation allows cross-tenant OVS port deletionEPSS 0.2%CVE-2026-47753MEDIUMIncus has a Nil-Pointer Dereference Panic via Instance Backup Import (volume omitted)EPSS 0.1%CVE-2026-32606HIGHIncusOS has a LUKS encryption bypass due to insufficient TPM policyEPSS 0.1%