cbcvebase.

Canonical Lxd vulnerabilities

41 known vulnerabilities affecting canonical/lxd.

Total CVEs
41
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH8MEDIUM15LOW2

Vulnerabilities

Page 2 of 3
CVE-2026-9640P3HIGHCVSS 7.2≥ 4.12, < 5.0.7≥ 5.21.0, < 5.21.5+2 more2026-06-26
CVE-2026-9640 [HIGH] CWE-863 CVE-2026-9640: A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5. A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies during snapshot restoration.. An authenticated project operator in a restricted multi-tenant environment can bypass policy restrictions by importing a maliciously crafted instance bac
nvd
CVE-2025-64507P3HIGHCVSS 8.6≥ 0, < 5.0.2-5+deb12u2≥ 0, < 5.0.2+git20231211.1364ae4-9+deb13u22025-11-10
CVE-2025-64507 [HIGH] CVE-2025-64507: Incus is a system container and virtual machine manager Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.19.0 affects any Incus user in an environment where an unprivileged user may have root access to a container with an attached custom storage volume that has the `security.shifted` property set to `true` as well as access to the host as an unprivileged user. The most common case for this would be systems us
osv
CVE-2025-54286P3HIGHCVSS 8.8≥ 5.0.0, < 5.0.5≥ 5.21.0, < 5.21.4+4 more2025-10-02
CVE-2025-54286 [HIGH] CWE-352 CVE-2025-54286: Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an atta Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances without user consent via crafted HTML form submissions exploiting client certificate authentication.
nvdosv
CVE-2025-54287P3MEDIUMCVSS 6.5≥ 4.0.0, < 5.21.4≥ 6.1, < 6.5+2 more2025-10-02
CVE-2025-54287 [MEDIUM] CWE-1336 CVE-2025-54287: Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attac Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance configuration permissions to read arbitrary files on the host system via specially crafted snapshot pattern templates using the Pongo2 template engine.
nvdosv
CVE-2025-54293P3MEDIUMCVSS 6.5≥ 4.0.0, < 5.21.4≥ 6.0, < 6.5+1 more2025-10-02
CVE-2025-54293 [MEDIUM] CWE-22 CVE-2025-54293: Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authentic Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attackers to read arbitrary files on the host system via crafted log file names or symbolic links.
nvdosv
CVE-2022-27664P3HIGHCVSS 7.5≥ 0, < 2.0.11-0ubuntu1~16.04.4+esm2≥ 0, < 3.0.3-0ubuntu1~18.04.2+esm22026-04-07
[HIGH] adsys, juju-core, lxd vulnerabilities adsys, juju-core, lxd vulnerabilities USN-8089-1 fixed vulnerabilities in Go Networking. This update provides the corresponding update to code vendored in LXD, ADSys, and Juju Core. Original advisory details: Bahruz Jabiyev, Tommaso Innocenti, Anthony Gavazzi, Steven Sprecher, and Kaan Onarlioglu discovered that servers using Go Networking could hang during shutdown if preempted by a fatal error. An attacker could possibly use this to cause a denia
osv
CVE-2025-54288P3MEDIUMCVSS 6.8≥ 4.0.0, < 5.21.4≥ 6.1, < 6.5+2 more2025-10-02
CVE-2025-54288 [MEDIUM] CWE-290 CVE-2025-54288: Information Spoofing in devLXD Server in Canonical LXD versions 4.0 and above on Linux container pla Information Spoofing in devLXD Server in Canonical LXD versions 4.0 and above on Linux container platforms allows attackers with root privileges within any container to impersonate other containers and obtain their metadata, configuration, and device information via spoofed process names in the command line.
nvdosv
CVE-2023-48733P4MEDIUMCVSS 6.7v5.0v5.212024-02-14
CVE-2023-48733 [MEDIUM] CWE-1188 CVE-2023-48733: An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.
nvd
CVE-2023-49721P4MEDIUMCVSS 6.7≥ 5.0.0, < 5.21.02024-02-14
CVE-2023-49721 [MEDIUM] CWE-276 CVE-2023-49721: An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.
nvd
CVE-2026-9639P4MEDIUMCVSS 6.5≥ 5.0.0, < 5.21.5≥ 6.0, < 6.9+1 more2026-06-26
CVE-2026-9639 [MEDIUM] CWE-476 CVE-2026-9639: Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux a Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted custom-volume backup tarball that omits the expires_at snapshot field.
nvd
CVE-2025-54291P4MEDIUMCVSS 5.3≥ 4.0.0, < 5.21.4≥ 6.1, < 6.5+2 more2025-10-02
CVE-2025-54291 [MEDIUM] CWE-209 CVE-2025-54291: Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remote attackers to determine project existence via differing HTTP status code responses.
nvd
CVE-2026-28385P4MEDIUMCVSS 5.0≥ 4.12, ≤ 6.9≥ 6.0, < 6.102026-06-26
CVE-2026-28385 [MEDIUM] CWE-918 CVE-2026-28385: In Canonical LXD versions 4.12 through 6.9, a Server-Side Request Forgery (SSRF) vulnerability in th In Canonical LXD versions 4.12 through 6.9, a Server-Side Request Forgery (SSRF) vulnerability in the image import functionality allows authenticated users with the can_create_images entitlement to interact with internal network infrastructure via the /images endpoint. When importing an image from a URL source, the LXD daemon fails to validate or re
nvd
CVE-2025-54290P4MEDIUMCVSS 5.3≥ 4.0.0, < 5.21.4≥ 6.1, < 6.5+2 more2025-10-02
CVE-2025-54290 [MEDIUM] CWE-200 CVE-2025-54290: Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows ne Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence without authentication via crafted requests using wildcard fingerprints.
nvd
CVE-2025-54292P4MEDIUMCVSS 4.6≥ 5.0.0, < 5.21.4≥ 6.0, < 6.5+1 more2025-10-02
CVE-2025-54292 [MEDIUM] CWE-22 CVE-2025-54292: Path traversal in Canonical LXD LXD-UI versions before 6.5 and 5.21.4 on all platforms allows remote Path traversal in Canonical LXD LXD-UI versions before 6.5 and 5.21.4 on all platforms allows remote authenticated attackers to access or modify unintended resources via crafted resource names embedded in URL paths.
nvd
CVE-2026-33542P4MEDIUMCVSS 5.7≥ 0, < 5.0.2-5+deb12u4≥ 0, < 5.0.2+git20231211.1364ae4-9+deb13u42026-03-26
CVE-2026-33542 [MEDIUM] CVE-2026-33542: Incus is a system container and virtual machine manager Incus is a system container and virtual machine manager. Prior to version 6.23.0, a lack of validation of the image fingerprint when downloading from simplestreams image servers opens the door to image cache poisoning and under very narrow circumstances exposes other tenants to running attacker controlled images rather than the expected one. Version 6.23.0 patches the issue.
osv
CVE-2016-1582P4MEDIUMCVSS 5.5v2.0.12016-06-09
CVE-2016-1582 [MEDIUM] CWE-200 CVE-2016-1582: LXD before 2.0.2 does not properly set permissions when switching an unprivileged container into pri LXD before 2.0.2 does not properly set permissions when switching an unprivileged container into privileged mode, which allows local users to access arbitrary world readable paths in the container directory via unspecified vectors.
nvdosv
CVE-2016-1581P4MEDIUMCVSS 5.5≤ 2.0.12016-06-09
CVE-2016-1581 [MEDIUM] CWE-284 CVE-2016-1581: LXD before 2.0.2 uses world-readable permissions for /var/lib/lxd/zfs.img when setting up a loop bas LXD before 2.0.2 uses world-readable permissions for /var/lib/lxd/zfs.img when setting up a loop based ZFS pool, which allows local users to copy and read data from arbitrary containers via unspecified vectors.
nvdosv
CVE-2026-63295P4MEDIUMCVSS 4.3≥ 4.0.0, < 4.0.12≥ 5.0.0, < 5.0.8+2 more2026-08-12
CVE-2026-63295 [MEDIUM] CWE-863 CVE-2026-63295: An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-leve An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions. When a project is configured with restrictions on container privileges (such as enforcing restricted.containers.privilege=isolated), LXD fails to enforce the requirement if an instance configuration omits the securi
nvd
CVE-2026-3351P4MEDIUMCVSS 4.3v6.62026-03-03
CVE-2026-3351 [MEDIUM] CWE-862 CVE-2026-3351: Improper authorization in the API endpoint GET /1.0/certificates in Canonical LXD 6.6 on Linux allow Improper authorization in the API endpoint GET /1.0/certificates in Canonical LXD 6.6 on Linux allows an authenticated, restricted user to enumerate all certificate fingerprints trusted by the lxd server.
nvd
CVE-2024-6156P4LOWCVSS 3.8≥ 4.0.0, < 4.0.10≥ 5.0.0, < 5.0.4+1 more2024-12-06
CVE-2024-6156 [LOW] CWE-295 CVE-2024-6156: Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's c Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.
nvd
Canonical Lxd vulnerabilities | cvebase