Linuxcontainers maintains a focused set of container and systems-management tools—including Incus, LXC, CGManager, and LXD—that operate at a privileged layer in Linux environments, where flaws can affect the isolation boundaries between containers and the host. The vendor's vulnerability footprint, while moderate in volume, sits among more prominent vendors in the landscape, reflecting the security-critical role these tools play in containerized infrastructure. Vulnerabilities affecting this vendor reach serious severity at a meaningful share and recur through weakness classes including NULL-pointer dereferences, resource-exhaustion conditions, authentication bypasses, certificate-validation gaps, and path-traversal flaws—all patterns endemic to privilege-boundary and isolation-enforcement code. Defenders running these tools should track updates closely, as flaws in container runtimes and management layers can undermine isolation assumptions across entire deployments. Current exploitation activity and severity distribution are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Linuxcontainers over time
Signals from CVEs in this vendor scope (32 CVEs).
32 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-5736HIGH runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveragi | Feb 11, 2019 | 8.6 | 91 | NO | YES |
CVE-2026-33945CRITICAL Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to systemd in the guest. For containers, this is handled through a sh | Mar 26, 2026 | 9.6 | 37 | NO | NO |
CVE-2026-33897CRITICAL Incus is a system container and virtual machine manager. Prior to version 6.23.0, instance template files can be used to cause arbitrary read or writes as root on the host server. | Mar 26, 2026 | 9.9 | 35 | NO | NO |
CVE-2026-33898HIGH Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui` incorrectly validates the authentication token such that a | Mar 27, 2026 | 8.8 | 31 | NO | NO |
CVE-2026-23954HIGH Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom image (e.g a member of the ‘inc | Jan 22, 2026 | 8.7 | 31 | NO | NO |
CVE-2026-23953HIGH Incus is a system container and virtual machine manager. In versions 6.20.0 and below, a user with the ability to launch a container with a custom YAML configuration (e.g a member | Jan 22, 2026 | 8.7 | 30 | NO | NO |
CVE-2016-10124HIGH An issue was discovered in Linux Containers (LXC) before 2016-02-22. When executing a program via lxc-attach, the nonpriv session can escape to the parent session by using the TIOC | Jan 9, 2017 | 8.6 | 28 | NO | NO |
CVE-2026-40197MEDIUM Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows an authenticated user with acc | May 6, 2026 | 6.5 | 27 | NO | NO |
CVE-2026-39402MEDIUM lxc is a Linux container runtime. In the setuid helper lxc-user-nic, the delete path contains a logic flaw in the find_line() function that allows an unprivileged user to delete OV | May 5, 2026 | 6.5 | 27 | NO | NO |
CVE-2026-33711HIGH Incus is a system container and virtual machine manager. Incus provides an API to retrieve VM screenshots. That API relies on the use of a temporary file for QEMU to write the scre | Mar 26, 2026 | 7.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (32 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Linuxcontainers.
Media articles that mention a CVE ID that affects a product developed by Linuxcontainers — matched by CVE ID, not by vendor name.