VYPR
Unrated severityNVD Advisory· Published Jun 27, 2026

Debian lxd: A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 b…

CVE-2026-9640

Description

A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies during snapshot restoration.. An authenticated project operator in a restricted multi-tenant environment can bypass policy restrictions by importing a maliciously crafted instance backup containing restricted configuration keys within a snapshot. When the snapshot is restored, these restricted keys are applied to the live instance without policy validation. Starting the modified instance grants the operator unauthorized host root access.

Affected products

2
  • Canonical/Lxdinferred
    Range: >=6.0,<6.9 || >=5.21.0,<5.21.5 || >=5.0.0,<5.0.7
  • LXD/LXDllm-create
    Range: >=6.0, <6.9; >=5.21.0, <5.21.5; >=5.0.0, <5.0.7

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.