[Git][security-tracker-team/security-tracker][master] Add new lxd issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 14 22:19:51 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
2c2cc5e5 by Salvatore Bonaccorso at 2026-08-14T23:19:34+02:00
Add new lxd issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1974,27 +1974,38 @@ CVE-2026-6821 (GitLab has remediated an issue in GitLab EE affecting all version
CVE-2026-67579 (Deserialization of Untrusted Data vulnerability in ash-project ash all ...)
NOT-FOR-US: ash-project ash
CVE-2026-66898 (A path traversal vulnerability in LXD allows an attacker to manipulate ...)
- TODO: check
+ - lxd <removed>
+ NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-m857-c7gc-c984
CVE-2026-65370 (ServiceTalk HTTP/1.x incorrectly handles malformed Transfer-Encoding w ...)
NOT-FOR-US: Apple
CVE-2026-64826 (rConfig before 8.2.13 contains a path traversal vulnerability that all ...)
NOT-FOR-US: rConfig
CVE-2026-63300 (An improper validation vulnerability in the instancePostMigration func ...)
- TODO: check
+ - lxd <removed>
+ NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-5g5r-wh97-qcq2
+ NOTE: https://github.com/canonical/lxd/pull/18605 (main)
+ NOTE: https://github.com/canonical/lxd/pull/18651 (stable-5.21)
CVE-2026-63299 (An authorization bypass vulnerability in LXD allows an authenticated u ...)
- TODO: check
+ - lxd <removed>
+ NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-5h78-p252-989h
CVE-2026-63298 (An improper neutralization of special elements vulnerability in LXD's ...)
- TODO: check
+ - lxd <removed>
+ NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-vfh7-q59q-54v2
CVE-2026-63297 (An authorization bypass vulnerability in LXD due to a timing flaw duri ...)
- TODO: check
+ - lxd <removed>
+ NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-v989-qw7w-xvg4
CVE-2026-63296 (An authorization bypass vulnerability in LXD allows an authenticated a ...)
- TODO: check
+ - lxd <removed>
+ NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-gcr9-5q6r-w625
CVE-2026-63295 (An authorization bypass vulnerability in LXD allows an authenticated a ...)
- TODO: check
+ - lxd <removed>
+ NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-7vp9-3vmp-c5jm
CVE-2026-63294 (A link following vulnerability in LXD allows an attacker to achieve ro ...)
- TODO: check
+ - lxd <removed>
+ NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-fv82-v4fj-mm4m
CVE-2026-63293 (A link following vulnerability in LXD allows an attacker to achieve ar ...)
- TODO: check
+ - lxd <removed>
+ NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-j825-cg34-5fr5
CVE-2026-62421
REJECTED
CVE-2026-62420 (An authorization bypass vulnerability in LXD allows an authenticated a ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2c2cc5e56023719350509553df06652c24a91b42
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2c2cc5e56023719350509553df06652c24a91b42
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/25633a82/attachment.htm>
More information about the debian-security-tracker-commits
mailing list