1.27.1

These release notes cover new features and changes in Anbox Cloud 1.27.1.

Anbox Cloud 1.27.1 is a patch release. To understand minor and patch releases, see Release notes.

Please see Component versions for a list of updated components.

Requirements

See the Requirements for details on general and deployment specific requirements to run Anbox Cloud.

New features & improvements

Deprecations and removed functionality

Android 12, Android 13, and AAOS 13 images are deprecated with the 1.27.1 release. The support for these images will be removed in 1.29.0.

Known issues

See our open bugs in Launchpad that are planned to be fixed in the upcoming releases.

The fix for RUSTSEC-2021-0154 CVE is not included in 1.27.1 because there was no upstream patch available when Anbox Cloud images were created for 1.27.1.

CVEs

The fixes for the following CVEs are included with the 1.27.1 release:

CVE

Affected components

CVE-2025-22441

Android 13, 14, 15

CVE-2025-48533

Android 13, 14, 15

CVE-2023-40078

AAOS 13

CVE-2023-21111

AAOS 13

CVE-2023-21103

AAOS 13

CVE-2023-21019

Android 13

CVE-2022-20124

Android 13

CVE-2023-20917

Android 13

CVE-2022-20483

Android 13

CVE-2024-43767

Android 12

CVE-2024-43097

Android 12

CVE-2021-0689

Android 12

CVE-2024-43768

Android 12

CVE-2025-27363

Android 12

CVE-2022-20496

Android 12

CVE-2025-26455

Android 12

CVE-2021-0506

Android 12

CVE-2025-22418

Android 12

CVE-2025-22427

Android 12

CVE-2025-26421

Android 12

CVE-2021-39629

Android 12

CVE-2024-34730

Android 12

CVE-2023-20936

Android 12

CVE-2023-20952

Android 12

CVE-2022-20461

Android 12

CVE-2022-40537

Android 12

CVE-2025-22435

Android 12

CVE-2025-26441

Android 12

CVE-2023-35657

Android 12

CVE-2025-26438

Android 12

CVE-2022-20467

Android 12

CVE-2025-26443

Android 12

CVE-2021-0959

Android 12

CVE-2021-0643

Android 12

CVE-2024-49720

Android 12

CVE-2025-26423

Android 12

CVE-2024-49730

Android 12

CVE-2025-22419

Android 12

CVE-2024-40653

Android 12

CVE-2025-26442

Android 12

CVE-2025-26426

Android 12

CVE-2022-20465

Android 12

CVE-2025-22433

Android 12

CVE-2025-22437

Android 12

CVE-2025-22442

Android 12

CVE-2025-22425

Android 12

CVE-2022-20007

Android 12

CVE-2025-22421

Android 12

CVE-2025-26436

Android 12

CVE-2023-21342

Android 12

CVE-2025-26428

Android 12

CVE-2023-20926

Android 12

CVE-2022-20414

Android 12

CVE-2025-26444

Android 12

CVE-2022-20144

Android 12

CVE-2021-0934

Android 12

CVE-2025-26448

Android 12

CVE-2025-26458

Android 12

CVE-2025-26463

Android 12

CVE-2025-32312

Android 12

CVE-2023-21089

AAOS 13

CVE-2023-35676

AAOS 13

CVE-2021-39810

Android 13, AAOS 13

CVE-2024-49714

Android 12, 13, 14, AAOS 13

CVE-2025-48542

Android 12, 13, 14, 15, AAOS 13

CVE-2025-48548

Android 12, 13, 14, 15, AAOS 13

CVE-2025-26454

Android 13, 14, 15, AAOS 13

CVE-2025-48529

Android 12, 13, 14, 15, AAOS 13

CVE-2025-48549

Android 12, 13, 14, 15, AAOS 13

CVE-2025-32346

Android 12, 13, 14, 15, AAOS 13

CVE-2025-22439

Android 12

CVE-2025-32326

Android 12, 13, 14, 15, AAOS 13

CVE-2025-48552

Android 12, 13, 14, 15, AAOS 13

CVE-2025-48527

Android 12, 13, 14, 15, AAOS 13

CVE-2025-0089

Android 12, 13, 14, 15, AAOS 13

CVE-2025-32321

Android 12, 13, 14, 15, AAOS 13

CVE-2025-48558

Android 12, 13, 14, 15, AAOS 13

CVE-2025-48528

Android 15

CVE-2025-48546

Android 12, 13, 14, 15, AAOS 13

CVE-2025-48523

Android 12, 13, 14, 15, AAOS 13

CVE-2025-32347

Android 12, 13, 14, 15, AAOS 13

CVE-2025-32330

Android 13, 14, 15, AAOS 13

CVE-2025-32327

Android 14, 15

CVE-2025-48531

Android 12, 13, 14, 15, AAOS 13

CVE-2025-48537

Android 12, 13, 14, 15, AAOS 13

CVE-2025-32323

Android 12, 13, 14, 15, AAOS 13

CVE-2025-48545

Android 12, 13, 14, 15, AAOS 13

CVE-2025-48524

Android 12, 13, 14, 15, AAOS 13

CVE-2025-48550

Android 12, 13, 14, 15, AAOS 13

CVE-2025-48563

Android 12, 13, 14, 15, AAOS 13

CVE-2025-32325

Android 13, 14, 15, AAOS 13

CVE-2025-32331

Android 15

CVE-2025-32324

Android 15

CVE-2025-48539

Android 15

CVE-2025-48526

Android 13, AAOS 13

CVE-2025-48551

Android 13

CVE-2025-32349

Android 12, 13, 14, 15, AAOS 13

CVE-2025-32345

Android 15

CVE-2025-48541

Android 13, 14, 15, AAOS 13

CVE-2025-48554

Android 12, 13, 14, 15, AAOS 13

CVE-2025-48544

Android 12, 13, 14, 15, AAOS 13

CVE-2025-48559

Android 12, 13, 14, 15, AAOS 13

CVE-2025-48540

Android 13, 14, 15, AAOS 13

CVE-2025-48522

Android 13, 14, 15, AAOS 13

CVE-2025-48547

Android 13, 14, 15, AAOS 13

CVE-2025-48560

Android 15

CVE-2025-48562

Android 12, 13, 14, 15, AAOS 13

CVE-2025-48535

Android 12, 13, 14, 15, AAOS 13

Bug fixes

  • LP 2119495 Changing screen resolution causes significant video stutter.

  • LP 2121502 With recent support for OIDC authentication, running amc exec causes AMC to crash.

  • LP 2121526 If an instance is being scheduled on a particular node, the worker node in AMS will stop scheduling it . If the scheduling happens while a node is temporarily off but the worker is running, the AMS worker becomes blocked until AMS is restarted.

  • LP 2097515 The SyncSensor thread is using up more than necessary CPU resources.

  • LP 2119723 While trying to delete an identity, AMC asks the user to confirm the deletion and then fails with a not found error. AMC doesn’t verify if the identity existed before confirming whether to delete it.

  • LP 2119726 The email address value for OIDC identities is not properly validated.

  • LP 2120611 Watchdog was triggered when launching 1.27.0 images.

  • LP 2119279 After restarting the AMS service, the metrics for number of containers in error status (ams_cluster_containers_per_status_total{status="error"}) will disappear for some time while the other metrics are available.

  • LP 2120677 On a machine with the nouveau driver installed and loaded, running the appliance prepare-node-script fails with a return code of 6. Rebooting fixes the problem, and the rest of the appliance can be initialized without any issue.

  • LP 2115864 Responsiveness of the dashboard’s side navigation when resizing windows is not good.

  • LP 2119724 The dashboard interface does not have a separator between the profile button and other buttons so that the action buttons can be viewed clearly.

  • LP 2119036 The Anbox Stream Gateway API for ADB shares GET call is incorrect.

  • LP 2109658 Private bug

  • LP 2118370 Private bug

Upgrade instructions

See How to upgrade Anbox Cloud for instructions on how to update your Anbox Cloud deployment to the 1.27.1 release.