CVE Tools

Apport

52 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Apport, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Apport CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Apport CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-012
2025-020
2025-030
2025-040
2025-051
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-121
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-081
2026-090

Severity

How the 52 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High3161%
  • Medium1325%
  • Low714%

Latest CVEs

The 15 most recently published vulnerabilities affecting Apport.

  1. CVE-2026-77113Path Traversal Vulnerability in apport-unpack—
  2. CVE-2025-5467Ubuntu Apport Insecure File Permissions Vulnerability3.3
  3. CVE-2025-5054Race Condition in Canonical Apport4.7
  4. CVE-2020-11936gdbus setgid privilege escalation3.1
  5. CVE-2022-28653Users can consume unlimited disk space in /var/crash7.5
  6. CVE-2022-28658Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing5.5
  7. CVE-2022-28657Apport does not disable python crash handler before entering chroot7.8
  8. CVE-2022-28656is_closing_session() allows users to consume RAM in the Apport process5.5
  9. CVE-2022-28655is_closing_session() allows users to create arbitrary tcp dbus connections7.1
  10. CVE-2022-28654is_closing_session() allows users to fill up apport.log5.5
  11. CVE-2022-28652~/.config/apport/settings parsing is vulnerable to "billion laughs" attack5.5
  12. CVE-2022-1242Apport can be tricked into connecting to arbitrary sockets as the root user7.8
  13. CVE-2021-3899There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary code as root.7.8
  14. CVE-2023-1326local privilege escalation in apport-cli7.7
  15. CVE-2021-3710Apport info disclosure via path traversal bug in read_file6.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store