VYPR
Medium severity6.5NVD Advisory· Published Jun 26, 2026· Updated Jul 2, 2026

CVE-2026-9639

CVE-2026-9639

Description

Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted custom-volume backup tarball that omits the expires_at snapshot field.

Affected products

3
  • Canonical/Lxdllm-fuzzy3 versions
    <=6.8, <=5.21+ 2 more
    • (no CPE)range: <=6.8, <=5.21
    • cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*range: >=5.0.0,<5.21.5
    • (no CPE)range: <= 6.8, <= 5.21

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.