Search CVE reports


Toggle filters

1 – 10 of 41 results


CVE-2026-84304

Medium priority
Needs evaluation

(gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, in ...)

3 affected packages

golang-google-grpc, google-guest-agent, grpc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-google-grpc Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
google-guest-agent Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
grpc Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-84303

Medium priority
Needs evaluation

(gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, th ...)

3 affected packages

golang-google-grpc, google-guest-agent, grpc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-google-grpc Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
google-guest-agent Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
grpc Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-56854

Medium priority
Needs evaluation

The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions...

4 affected packages

golang-go.crypto, snapd, lxd, google-guest-agent

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-go.crypto Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
snapd Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
lxd Not in release Not in release Not in release Not affected Needs evaluation
google-guest-agent Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-39824

Medium priority
Needs evaluation

NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error.

2 affected packages

golang-golang-x-sys, google-guest-agent

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-golang-x-sys Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
google-guest-agent Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-46598

Medium priority
Needs evaluation

For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, leading to a panic when used.

4 affected packages

golang-go.crypto, snapd, google-guest-agent, lxd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-go.crypto Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
snapd Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
google-guest-agent Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
lxd Not in release Not in release Not in release Not affected Needs evaluation
Show less packages

CVE-2026-46597

Medium priority
Needs evaluation

An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.

4 affected packages

golang-go.crypto, snapd, google-guest-agent, lxd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-go.crypto Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
snapd Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
google-guest-agent Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
lxd Not in release Not in release Not in release Not affected Needs evaluation
Show less packages

CVE-2026-46595

Medium priority

Some fixes available 4 of 12

Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.

4 affected packages

golang-go.crypto, snapd, lxd, google-guest-agent

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-go.crypto Fixed Not affected Not affected Not affected Not affected
snapd Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
lxd Not in release Not in release Not in release Not affected Not affected
google-guest-agent Fixed Fixed Not affected Not affected Not affected
Show less packages

CVE-2026-42508

Medium priority

Some fixes available 7 of 15

Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.

4 affected packages

golang-go.crypto, snapd, lxd, google-guest-agent

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-go.crypto Fixed Fixed Fixed Fixed Fixed
snapd Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
lxd Not in release Not in release Not in release Not affected Fixed
google-guest-agent Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2026-39835

Medium priority
Needs evaluation

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking...

4 affected packages

golang-go.crypto, snapd, google-guest-agent, lxd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-go.crypto Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
snapd Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
google-guest-agent Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
lxd Not in release Not in release Not in release Not affected Needs evaluation
Show less packages

CVE-2026-39834

Medium priority

Some fixes available 15 of 23

When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the write loop to spin indefinitely, sending empty packets without making progress....

4 affected packages

golang-go.crypto, snapd, lxd, google-guest-agent

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-go.crypto Fixed Fixed Fixed Fixed Fixed
snapd Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
lxd Not in release Not in release Not in release Not affected Fixed
google-guest-agent Fixed Fixed Fixed Fixed Fixed
Show less packages