Skip to main content

Vendor/product archive

canonical / apport CVEs

Beta · best-effort

17 CVEs tagged to canonical / apport0 Critical, 9 High, 5 Medium, 3 Low, 0 Unrated.

CVE-2025-5467

Published Dec 10, 2025

It was discovered that process_crash() in data/apport in Canonical's Apport crash reporting tool may create crash files with incorrect group ownership, possibly exposing crash inf…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-5054

Published May 30, 2025

Race condition in Canonical apport up to and including 2.32.0 allows a local attacker to leak sensitive information via PID-reuse by leveraging namespaces. When handling a cra…

CVSS 4.7 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2022-28653

Published Jan 31, 2025

Users can consume unlimited disk space in /var/crash

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-1326

Published Apr 13, 2023

A privilege escalation attack was found in apport-cli 2.26.0 and earlier which is similar to CVE-2023-26604. If a system is specially configured to allow unprivileged users to run…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32557

Published Jun 12, 2021

It was discovered that the process_report() function in data/whoopsie-upload-all allowed arbitrary file writes via symlinks.

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32556

Published Jun 12, 2021

It was discovered that the get_modified_conffiles() function in backends/packaging-apt-dpkg.py allowed injecting modified package names in a manner that would confuse the dpkg(1)…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-25684

Published Jun 11, 2021

It was discovered that apport in data/apport did not properly open a report file to prevent hanging reads on a FIFO.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25683

Published Jun 11, 2021

It was discovered that the get_starttime() function in data/apport did not properly parse the /proc/pid/stat file from the kernel.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25682

Published Jun 11, 2021

It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15702

Published Aug 6, 2020

TOCTOU Race Condition vulnerability in apport allows a local attacker to escalate privileges and execute arbitrary code. An attacker may exit the crashed process and exploit PID r…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15701

Published Aug 6, 2020

An unhandled exception in check_ignored() in apport/report.py can be exploited by a local attacker to cause a denial of service. If the mtime attribute is a string value in apport…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1341

Published Apr 22, 2019

Any Python module in sys.path can be imported if the command line of the process triggering the coredump is Python and the first argument is -m in Apport before 2.19.2 function _p…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort
Showing 1-17 of 17 CVEsPage 1 of 1