cbcvebase.

Canonical Lxd vulnerabilities

41 known vulnerabilities affecting canonical/lxd.

Total CVEs
41
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH8MEDIUM15LOW2

Vulnerabilities

Page 1 of 3
CVE-2026-63294P2CRITICALCVSS 9.9≥ 4.0.0, < 4.0.12≥ 5.0.0, < 5.0.8+2 more2026-08-12
CVE-2026-63294 [CRITICAL] CWE-59 CVE-2026-63294: A link following vulnerability in LXD allows an attacker to achieve root command execution on the ho A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and confine the backup.yaml file when it exists as a symbolic link. An attacker can exploit this flaw by providing a malicious archive with
nvd
CVE-2026-33897P2CRITICALCVSS 9.9≥ 0, < 5.0.2-5+deb12u4≥ 0, < 5.0.2+git20231211.1364ae4-9+deb13u42026-03-26
CVE-2026-33897 [CRITICAL] CVE-2026-33897: Incus is a system container and virtual machine manager Incus is a system container and virtual machine manager. Prior to version 6.23.0, instance template files can be used to cause arbitrary read or writes as root on the host server. Incus allows for pongo2 templates within instances which can be used at various times in the instance lifecycle to template files inside of the instance. This particular implementation of pongo2 within Incus allowed for fi
osv
CVE-2026-63298P2CRITICALCVSS 9.9≥ 5.0.0, < 5.0.8≥ 5.21.0, < 5.21.6+1 more2026-08-12
CVE-2026-63298 [CRITICAL] CWE-78 CVE-2026-63298: An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline characters within the 'nvidia.driver.capabilities' or 'nvidia.require.*' configuration values, an attacker can manipulate the generated lxc.co
nvd
CVE-2026-66897P2CRITICALCVSS 9.9≥ 4.0.0, < 4.0.13≥ 5.0.0, < 5.0.9+2 more2026-08-24
CVE-2026-66897 [CRITICAL] CWE-22 CVE-2026-66897: A path traversal vulnerability in LXD's instance template processing allows an attacker with contain A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target template paths specified in metadata.yaml, LXD validates the path against a confined os.Root directory handle
nvd
CVE-2026-63299P2CRITICALCVSS 9.9≥ 5.0.0, < 5.0.8≥ 5.21.0, < 5.21.6+1 more2026-08-12
CVE-2026-63299 [CRITICAL] CWE-770 CVE-2026-63299: An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level di An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource limits during volume operations: the storagePoolVolumeTypePostMove function omits the limits.AllowVolumeCreation check before moving a volume across projects, and volume snapshot r
nvd
CVE-2026-63293P2CRITICALCVSS 9.9≥ 4.0.0, < 4.0.12≥ 5.0.0, < 5.0.8+2 more2026-08-12
CVE-2026-63293 [CRITICAL] CWE-59 CVE-2026-63293: A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write op A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate whether the metadata.yaml file is a symbolic link. An attacker can exploit this flaw by providing a crafted image archive with a symlinked metadata.yaml
nvd
CVE-2026-66898P2CRITICALCVSS 9.9≥ 4.0.0, < 4.0.12≥ 5.0.0, < 5.0.4+2 more2026-08-12
CVE-2026-66898 [CRITICAL] CWE-22 CVE-2026-66898: A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during back A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive wit
nvd
CVE-2026-63300P2CRITICALCVSS 9.9≥ 5.0.0, < 5.0.8≥ 5.21.0, < 5.21.6+1 more2026-08-12
CVE-2026-63300 [CRITICAL] CWE-862 CVE-2026-63300: An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go o An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level security restrictions. When migrating an instance between projects, LXD fails to validate the instance's configuration again
nvd
CVE-2026-63297P2CRITICALCVSS 9.9≥ 5.0.0, < 5.0.8≥ 5.21.0, < 5.21.62026-08-12
CVE-2026-63297 [CRITICAL] CWE-367 CVE-2026-63297: An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allow An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a target project, LXD performs restriction checks before configuration merging is complete, creating a time-of-check
nvd
CVE-2026-62420P2CRITICALCVSS 9.9≥ 5.0.0, < 5.0.8≥ 5.21.0, < 5.21.6+1 more2026-08-12
CVE-2026-62420 [CRITICAL] CWE-863 CVE-2026-62420: An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target proje An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member via POST /1.0/instances/{name} with migration: true, project: , and target: , the destination node skips all proje
nvd
CVE-2026-63296P2CRITICALCVSS 9.9≥ 5.0.0, < 5.0.8≥ 5.21.0, < 5.21.6+1 more2026-08-12
CVE-2026-63296 [CRITICAL] CWE-863 CVE-2026-63296: An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target proje An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the target project's enforced restrictions. An attacker can exploit this
nvd
CVE-2026-28384P2CRITICALCVSS 9.4≥ 6.0, < 6.7≥ 5.21.0, < 5.21.4+2 more2026-03-12
CVE-2026-28384 [CRITICAL] CWE-78 CVE-2026-28384: An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authentic An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup endpoints. This issue affected LXD from 4.12 through 6.6 and was fixed in the snap versions 5.0.6-e49d9f4 (channel 5.0/stable), 5.21
nvdosv
CVE-2026-12411P3CRITICALCVSS 9.6≥ 6.6, < 6.92026-06-26
CVE-2026-12411 [CRITICAL] CWE-639 CVE-2026-12411: Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrust Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when security.devlxd.management.volumes is enabled.
nvd
CVE-2026-23954P3HIGHCVSS 8.7≥ 0, < 5.0.2-5+deb12u3≥ 0, < 5.0.2+git20231211.1364ae4-9+deb13u32026-01-22
CVE-2026-23954 [HIGH] CVE-2026-23954: Incus is a system container and virtual machine manager Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom image (e.g a member of the ‘incus’ group) to use directory traversal or symbolic links in the templating functionality to achieve host arbitrary file read, and host arbitrary file write. This ultimately results in arbitrary command execution on the host. Wh
osv
CVE-2026-16033P3HIGHCVSS 8.5≥ 4.0.0, < 4.0.12≥ 5.0.0, < 5.0.82026-08-12
CVE-2026-16033 [HIGH] CWE-22 CVE-2026-16033: A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unco A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths from escaping the instance templates directory (specifically affecting virtual machine / QEMU driver execution paths). An at
nvd
CVE-2026-23953P3HIGHCVSS 8.7≥ 0, < 5.0.2-5+deb12u3≥ 0, < 5.0.2+git20231211.1364ae4-9+deb13u32026-01-22
CVE-2026-23953 [HIGH] CVE-2026-23953: Incus is a system container and virtual machine manager Incus is a system container and virtual machine manager. In versions 6.20.0 and below, a user with the ability to launch a container with a custom YAML configuration (e.g a member of the ‘incus’ group) can create an environment variable containing newlines, which can be used to add additional configuration items in the container’s lxc.conf due to newline injection. This can allow adding arbitrary lifecy
osv
CVE-2026-34177P3CRITICALCVSS 9.1≥ 4.12, ≤ 5.0.6≥ 5.21.0, ≤ 5.21.4+4 more2026-04-09
CVE-2026-34177 [CRITICAL] CWE-184 CVE-2026-34177: Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidde Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limits/permissions.go), which omits raw.apparmor and raw.qemu.conf from the set of keys blocked under the restricted.virtual-machines.lowlevel=block project restriction. A remote attacker with can_edit permission on a VM instance in a
nvd
CVE-2025-54289P3HIGHCVSS 8.1≥ 4.0.0, < 5.21.4≥ 6.1, < 6.5+2 more2025-10-02
CVE-2025-54289 [HIGH] CWE-1385 CVE-2025-54289: Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker w Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read permissions to hijack terminal or console sessions and execute arbitrary commands via WebSocket connection hijacking format
nvd
CVE-2026-34178P3CRITICALCVSS 9.1≥ 4.12, ≤ 5.0.6≥ 5.21.0, ≤ 5.21.4+4 more2026-04-09
CVE-2026-34178 [CRITICAL] CWE-20 CVE-2026-34178: In Canonical LXD before 6.8, the backup import path validates project restrictions against backup/in In Canonical LXD before 6.8, the backup import path validates project restrictions against backup/index.yaml in the supplied tar archive but creates the instance from backup/container/backup.yaml, a separate file in the same archive that is never checked against project restrictions. An authenticated remote attacker with instance-creation permissio
nvd
CVE-2026-34179P3CRITICALCVSS 9.1≥ 4.12, ≤ 5.0.6≥ 5.21.0, ≤ 5.21.4+4 more2026-04-09
CVE-2026-34179 [CRITICAL] CWE-915 CVE-2026-34179: In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PUT/PATCH requests to /1.0/certificates/{fingerprint} for restricted TLS certificate users, allowing a remote authenticated attacker to escalate privileges to cluster admin.
nvd
Canonical Lxd vulnerabilities | cvebase