Where
-Infinity
0

Vendor Risk Score

See how linuxcontainers compares to other vendors in security performance

View Risk Score →

LXC lxc-user-niclxc lxc-user-nic insufficient ownership validation allows cross-tenant OVS port deletion

Risk 36
Severity
4.3
First published (updated )

go/github.com/lxc/incus/v6/cmd/incusdIncus: Unbounded binary import disk exhaustion

Risk 22
Severity
4.3
First published (updated )

go/github.com/lxc/incus/v6/cmd/incusdIncus: Nil Dereferences on Restore via Malformed YAML

Risk 38
Severity
6.5
First published (updated )

go/github.com/lxc/incus/v6/cmd/incusdIncus: Unbounded YAML Metadata Decode via Parsing

Risk 26
Severity
5.3
First published (updated )

go/github.com/lxc/incus/v6/cmd/incusdIncus: Nil-Pointer Dereference via S3 Bucket Import

Risk 38
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/github.com/lxc/incus/v6/cmd/incusdIncus out-of-bounds panic in snapshot metadata handling allows denial of service

Risk 40
Severity
7.1
First published (updated )

go/github.com/lxc/incus/v6/cmd/incusdIncus OVN TLS verification accepts peer-supplied roots and permits endpoint impersonation

Risk 32
Severity
2.3
First published (updated )

go/github.com/lxc/incus/v6/cmd/incusdIncus nil-pointer dereference in custom volume import allows denial of service

Risk 40
Severity
7.1
First published (updated )

go/github.com/lxc/incus/v6/cmd/incusdIncus nil-pointer dereference in storage bucket import allows denial of service

Risk 40
Severity
7.1
First published (updated )

go/github.com/lxc/incus/v6/cmd/incusdIncus blind SSRF via image import preflight HEAD request

Risk 27
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Linux Containers IncusAbitrary file write through systemd-creds option

Risk 59
Severity
10
EPSS
0.06%
First published (updated )

Incus IncusLocal Incus UI web server vulnerable to nuthentication bypass

Risk 56
Severity
8.8
EPSS
0.06%
First published (updated )

Canonical IncusIncus vulnerable to arbitrary file read and write through pongo templates

Risk 59
Severity
10
EPSS
0.05%
First published (updated )

Canonical IncusIncus vulnerable to denial of source through crafted bucket backup file

Risk 27
Severity
6.5
EPSS
0.04%
First published (updated )

Incus IncusIncus vulnerable to local privilege escalation through VM screenshot path

Risk 51
Severity
4.7
EPSS
0.01%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Incus IncusIncus does not verify combined fingerprint when downloading images from simplestreams servers

Risk 40
Severity
5.7
First published (updated )

go/github.com/lxc/incus/v6/cmd/incusdIncus container image templating arbitrary host file read and write

Risk 45
Severity
8.7
EPSS
0.04%
First published (updated )

go/github.com/lxc/incus/v6Incus container environment configuration newline injection

Risk 45
Severity
8.7
EPSS
0.02%
First published (updated )

go/github.com/lxc/incus/v6Incus vulnerable to local privilege escalation through custom storage volumes

Risk 76
Severity
8.6
First published (updated )

linuxcontainers Lxclxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer wheth…

Risk 18
Severity
3.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

linuxcontainers LxcIn LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature ch…

Risk 79
Severity
8.1
First published (updated )

go/github.com/lxc/lxdchmod race in doUidshiftIntoContainer

Risk 76
Severity
8.1
First published (updated )

linuxfoundation RuncOS Command Injection

Risk 83
Severity
8.6
First published (updated )

linuxcontainers LxcThe lxc-user-nic component of LXC allows unprivileged users to open arbitrary files

Risk 18
Severity
3.3
First published (updated )

linuxcontainers Lxclxc-user-nic in Linux Containers (LXC) allows local users with a lxc-usernet allocation to create ne…

Risk 18
Severity
3.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

linuxcontainers LxcAn issue was discovered in Linux Containers (LXC) before 2016-02-22. When executing a program via lx…

Risk 49
Severity
8.6
First published (updated )

debian/lxclxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged con…

Risk 75
Severity
9.1
First published (updated )

linuxcontainers Lxclxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape…

Risk 63
Severity
7.2
First published (updated )

linuxcontainers Lxclxclock.c in LXC 1.1.2 and earlier allows local users to create arbitrary files via a symlink attack…

Risk 28
Severity
4.9
First published (updated )

linuxcontainers Lxcattach.c in LXC 1.1.2 and earlier uses the proc filesystem in a container, which allows local contai…

Risk 34
Severity
4.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203