CVE-2019-11480: Canonical C-Kernel
High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.
The pc-kernel snap build process hardcoded the --allow-insecure-repositories and --allow-unauthenticated apt options when creating the build chroot environment. This could allow an attacker who is able to perform a MITM attack between the build environment and the Ubuntu archive to install a malicious package within the build chroot. This issue affects pc-kernel versions prior to and including 2019-07-16
Affected products
- Canonical C-Kernel: up to and including 2019-07-16
Published 2020-04-14. Last modified 2026-06-17.