Canonical Ltd.
First CVE: Dec 31, 2004Active for: 22 years
506
CVEs Published
More CVEs Published than 86% of tracked CNAs
23.0
Avg CVEs / Year
More Avg CVEs / Year than 71% of tracked CNAs
6.2
Avg CVSS Score
Higher Avg CVSS Score than 15% of tracked CNAs
0.6%
In CISA KEV
Higher KEV Rate than 86% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by Canonical Ltd. as a CNA, 60.3% affect products that Canonical Ltd. develops as a vendor.
60.3%
39.7%
Self-reported: 305Third-party: 201
Of all the CVEs published that affect products developed by Canonical Ltd., 7.1% are self-published by Canonical Ltd. as a CNA.
92.9%
Self-published: 305Published by other CNAs: 4,003
Trends Over Time
The number and severity of CVEs published by Canonical Ltd. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2004
21 years ago
Most Recent CVE
Jul 21, 2026
3 days ago
Top CVEs
All CVEs published by Canonical Ltd. as a CNA, regardless of affected vendor or product.
506 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3493HIGH The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. D | Apr 17, 2021 | 7.8 | 89 | YES | YES |
CVE-2010-3904HIGH The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addres | Dec 6, 2010 | 7.8 | 84 | YES | YES |
CVE-2019-11477HIGH Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). | Jun 19, 2019 | 7.5 | 78 | NO | NO |
CVE-2019-11478HIGH Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgme | Jun 19, 2019 | 7.5 | 76 | NO | NO |
CVE-2007-5208HIGH hpssd in Hewlett-Packard Linux Imaging and Printing Project (hplip) 1.x and 2.x before 2.7.10 allows context-dependent attackers to execute arbitrary commands via shell metacharact | Oct 13, 2007 | 7.6 | 76 | NO | YES |
CVE-2019-11479HIGH Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger | Jun 19, 2019 | 7.5 | 75 | NO | NO |
CVE-2022-2586HIGH It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted. | Jan 8, 2024 | 7.8 | 68 | YES | NO |
CVE-2019-7304CRITICAL Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root. This issue affects: Canonical snapd ver | Apr 23, 2019 | 9.8 | 66 | NO | YES |
CVE-2015-1328HIGH The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does not properly check permissions for file creation in the upper | Nov 28, 2016 | 7.8 | 66 | NO | YES |
CVE-2023-2640HIGH On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlayfs.* xattrs", an unprivileged user may set privileged extend | Jul 26, 2023 | 7.8 | 54 | NO | YES |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA506 CVEs
13%
45%
37%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local263 (52.0%)
Network98 (19.4%)
Unknown137 (27.1%)
Physical3 (0.6%)
Adjacent Network4 (0.8%)
Attack Complexity
Low312 (61.7%)
High57 (11.3%)
Unknown137 (27.1%)
User Interaction
None332 (65.6%)
Unknown137 (27.1%)
Required37 (7.3%)
Privileges Required
Low259 (51.2%)
High26 (5.1%)
None84 (16.6%)
Unknown137 (27.1%)
Exploit Exposure
Signals from CVEs in this cna scope (506 CVEs).
CISA KEV
3 CVEs
0.6% of CVEs· 86th percentile
Metasploit
9 CVEs
1.8% of CVEs· 91st percentile
Nuclei
1 CVE
0.2% of CVEs· 71st percentile
ExploitDB
28 CVEs
5.5% of CVEs· 96th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Canonical Ltd. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Canonical Ltd. as a CNA — matched by CVE ID, not by organization name.