PT-2025-40333 · Canonical+2 · Lxd+2

CVE-2025-54290

·

Published

2025-10-02

·

Updated

2026-07-30

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Canonical LXD versions prior to 6.5 Canonical LXD versions prior to 5.21.4
Description An information disclosure issue exists in the image export API of Canonical LXD. A network attacker can determine project existence without authentication by sending crafted requests that utilize wildcard fingerprints. The issue affects systems running on Linux.
Recommendations Update to a version of Canonical LXD 6.5 or later. Update to a version of Canonical LXD 5.21.4 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-54290
DSA-6027-1
GHSA-P3X5-MVMP-5F35
GO-2025-4002
OPENSUSE-SU-2025:15710-1
OPENSUSE-SU-2026:21483-1

Affected Products

Debian
Lxd
Red Os