Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Linuxcontainers

First CVE: Feb 14, 2014Active for: 12 yearsTotal CVEs: 32
37.4
VTI Score
Medium

Linuxcontainers maintains a focused set of container and systems-management tools—including Incus, LXC, CGManager, and LXD—that operate at a privileged layer in Linux environments, where flaws can affect the isolation boundaries between containers and the host. The vendor's vulnerability footprint, while moderate in volume, sits among more prominent vendors in the landscape, reflecting the security-critical role these tools play in containerized infrastructure. Vulnerabilities affecting this vendor reach serious severity at a meaningful share and recur through weakness classes including NULL-pointer dereferences, resource-exhaustion conditions, authentication bypasses, certificate-validation gaps, and path-traversal flaws—all patterns endemic to privilege-boundary and isolation-enforcement code. Defenders running these tools should track updates closely, as flaws in container runtimes and management layers can undermine isolation assumptions across entire deployments. Current exploitation activity and severity distribution are shown alongside this summary.

FAUCET AI Generated
32
Total CVEs
More Total CVEs than 97% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Linuxcontainers over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 14, 2014
12 years ago
Most Recent CVE
May 7, 2026
78 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (32 CVEs).

32 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-5736HIGH
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveragi
Feb 11, 20198.691NOYES
CVE-2026-33945CRITICAL
Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to systemd in the guest. For containers, this is handled through a sh
Mar 26, 20269.637NONO
CVE-2026-33897CRITICAL
Incus is a system container and virtual machine manager. Prior to version 6.23.0, instance template files can be used to cause arbitrary read or writes as root on the host server.
Mar 26, 20269.935NONO
CVE-2026-33898HIGH
Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui` incorrectly validates the authentication token such that a
Mar 27, 20268.831NONO
CVE-2026-23954HIGH
Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom image (e.g a member of the ‘inc
Jan 22, 20268.731NONO
CVE-2026-23953HIGH
Incus is a system container and virtual machine manager. In versions 6.20.0 and below, a user with the ability to launch a container with a custom YAML configuration (e.g a member
Jan 22, 20268.730NONO
CVE-2016-10124HIGH
An issue was discovered in Linux Containers (LXC) before 2016-02-22. When executing a program via lxc-attach, the nonpriv session can escape to the parent session by using the TIOC
Jan 9, 20178.628NONO
CVE-2026-40197MEDIUM
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows an authenticated user with acc
May 6, 20266.527NONO
CVE-2026-39402MEDIUM
lxc is a Linux container runtime. In the setuid helper lxc-user-nic, the delete path contains a logic flaw in the find_line() function that allows an unprivileged user to delete OV
May 5, 20266.527NONO
CVE-2026-33711HIGH
Incus is a system container and virtual machine manager. Incus provides an API to retrieve VM screenshots. That API relies on the use of a temporary file for QEMU to write the scre
Mar 26, 20267.827NONO
View all 32 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products32 CVEs
13%
44%
34%
9%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local7 (21.9%)
Network18 (56.3%)
Unknown5 (15.6%)
Physical0 (0.0%)
Adjacent Network2 (6.3%)
Attack Complexity
Low23 (71.9%)
High4 (12.5%)
Unknown5 (15.6%)
User Interaction
None25 (78.1%)
Unknown5 (15.6%)
Required2 (6.3%)
Privileges Required
Low19 (59.4%)
High1 (3.1%)
None7 (21.9%)
Unknown5 (15.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (32 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
3.1% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
3.1% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Linuxcontainers.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Linuxcontainers — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Linuxcontainers's Products

View all 4 CNAs →

Top CWEs