CVE-2024-6219
published 2024-12-06CVE-2024-6219: Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not…
PriorityP412low3.8CVSS 3.1
AVLACLPRLUINSCCLINAN
EPSS
0.16%
5.1th percentile
Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | lxd | < 5.21.1 | 5.21.1 |
| canonical_ltd | lxd | < 5.21.1 | 5.21.1 |
| debian | incus | — | — |
| debian | lxd | — | — |
| github.com | canonical_lxd | >= 0 < 0.0.0-20240403103450-0e7f2b5bf4d2 | 0.0.0-20240403103450-0e7f2b5bf4d2 |
CVSS provenance
nvdv3.13.8LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
osv3.8LOW
vendor_debian3.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
lxd has a restricted TLS certificate privilege escalation when in PKI mode
osv·2024-12-09
CVE-2024-6219 [LOW] lxd has a restricted TLS certificate privilege escalation when in PKI mode
lxd has a restricted TLS certificate privilege escalation when in PKI mode
### Summary
If a `server.ca` file is present in `LXD_DIR` at LXD start up, LXD is in "PKI mode". In this mode, all clients must have certificates that have been signed by the CA.
The LXD configuration option `core.trust_ca_certificates` defaults to `false`. This means that although the client certificate has been signed by the CA, LXD will additionally add the certificate to the trust store and verify it via mTLS.
When a restricted certificate is added to the trust store in this mode, it's restrictions are not honoured, and the client has full access to LXD.
### Details
When authorization was refactored to allow for generalisation (at the time for TLS, RBAC, and OpenFGA, see https://github.com/canonical/lxd/pull
GHSA
lxd has a restricted TLS certificate privilege escalation when in PKI mode
ghsa·2024-12-09
CVE-2024-6219 [LOW] CWE-287 lxd has a restricted TLS certificate privilege escalation when in PKI mode
lxd has a restricted TLS certificate privilege escalation when in PKI mode
### Summary
If a `server.ca` file is present in `LXD_DIR` at LXD start up, LXD is in "PKI mode". In this mode, all clients must have certificates that have been signed by the CA.
The LXD configuration option `core.trust_ca_certificates` defaults to `false`. This means that although the client certificate has been signed by the CA, LXD will additionally add the certificate to the trust store and verify it via mTLS.
When a restricted certificate is added to the trust store in this mode, it's restrictions are not honoured, and the client has full access to LXD.
### Details
When authorization was refactored to allow for generalisation (at the time for TLS, RBAC, and OpenFGA, see https://github.com/canonical/lxd/pull
OSV
Restricted TLS certificate privilege escalation when in PKI mode in github.com/canonical/lxd
osv·2024-12-09
CVE-2024-6219 Restricted TLS certificate privilege escalation when in PKI mode in github.com/canonical/lxd
Restricted TLS certificate privilege escalation when in PKI mode in github.com/canonical/lxd
Restricted TLS certificate privilege escalation when in PKI mode in github.com/canonical/lxd
OSV
CVE-2024-6219: Mark Laing discovered in LXD's PKI mode, until version 5
osv·2024-12-06·CVSS 3.8
CVE-2024-6219 [LOW] CVE-2024-6219: Mark Laing discovered in LXD's PKI mode, until version 5
Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.
Debian
CVE-2024-6219: incus - Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted...
vendor_debian·2024·CVSS 3.8
CVE-2024-6219 [LOW] CVE-2024-6219: incus - Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted...
Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.
Scope: local
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-12-06
Published