VYPR

Lxd

by Canonical

Source repositories

CVEs (35)

  • CVE-2026-66898CriAug 12, 2026
    risk 0.64cvss 9.9epss

    A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An…

  • CVE-2026-63300CriAug 12, 2026
    risk 0.64cvss 9.9epss

    An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level security restrictions. When migrating an instance…

  • CVE-2026-63299CriAug 12, 2026
    risk 0.64cvss 9.9epss

    An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource limits during volume operations: the storagePoolVolumeTypePostMove function omits the…

  • CVE-2026-63298CriAug 12, 2026
    risk 0.64cvss 9.9epss

    An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline characters within the 'nvidia.driver.capabilities' or…

  • CVE-2026-63297CriAug 12, 2026
    risk 0.64cvss 9.9epss

    An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a target project, LXD performs restriction…

  • CVE-2026-63296CriAug 12, 2026
    risk 0.64cvss 9.9epss

    An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the…

  • CVE-2026-63294CriAug 12, 2026
    risk 0.64cvss 9.9epss

    A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and confine the backup.yaml file when it exists as a symbolic link.…

  • CVE-2026-63293CriAug 12, 2026
    risk 0.64cvss 9.9epss

    A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate whether the metadata.yaml file is a symbolic link. An attacker can exploit this…

  • CVE-2026-62420CriAug 12, 2026
    risk 0.64cvss 9.9epss

    An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member via POST /1.0/instances/{name} with…

  • CVE-2025-54286HigOct 2, 2025
    risk 0.57cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances without user consent via crafted HTML form submissions exploiting client certificate authentication.

  • CVE-2026-16033HigAug 12, 2026
    risk 0.55cvss 8.5epss

    A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths from escaping the instance templates directory…

  • CVE-2025-54289HigOct 2, 2025
    risk 0.53cvss 8.1epss 0.00

    Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read permissions to hijack terminal or console sessions and execute arbitrary commands via WebSocket connection hijacking format

  • CVE-2026-34179CriApr 9, 2026
    risk 0.52cvss 9.1epss 0.00

    In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PUT/PATCH requests to /1.0/certificates/{fingerprint} for restricted TLS certificate users, allowing a remote authenticated attacker…

  • CVE-2026-34178CriApr 9, 2026
    risk 0.52cvss 9.1epss 0.00

    In Canonical LXD before 6.8, the backup import path validates project restrictions against backup/index.yaml in the supplied tar archive but creates the instance from backup/container/backup.yaml, a separate file in the same archive that is never checked against project…

  • CVE-2026-34177CriApr 9, 2026
    risk 0.52cvss 9.1epss 0.00

    Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limits/permissions.go), which omits raw.apparmor and raw.qemu.conf from the set of keys blocked under the restricted.virtual-machines.lowlevel=block project…

  • CVE-2026-12411HigJun 26, 2026
    risk 0.48cvss 8.4epss 0.00

    Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when security.devlxd.management.volumes is enabled.

  • CVE-2025-54288MedOct 2, 2025
    risk 0.44cvss 6.8epss 0.00

    Information Spoofing in devLXD Server in Canonical LXD versions 4.0 and above on Linux container platforms allows attackers with root privileges within any container to impersonate other containers and obtain their metadata, configuration, and device information via spoofed…

  • CVE-2023-49721MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.

  • CVE-2023-48733MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.

  • CVE-2025-54287MedOct 2, 2025
    risk 0.42cvss 6.5epss 0.00

    Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance configuration permissions to read arbitrary files on the host system via specially crafted snapshot pattern templates using the Pongo2 template engine.

Page 1 of 2