High severity8.4NVD Advisory· Published Jun 26, 2026· Updated Jul 2, 2026
CVE-2026-12411
CVE-2026-12411
Description
Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when security.devlxd.management.volumes is enabled.
Affected products
2Patches
Vulnerability mechanics
References
2- github.com/canonical/lxd/pull/18585nvdIssue TrackingPatch
- github.com/canonical/lxd/security/advisories/GHSA-hhf9-qw4v-72xpnvdExploitVendor Advisory
News mentions
0No linked articles in our index yet.