PT-2026-52844 · Canonical · Lxd
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LXD versions 6.0 through 6.8
LXD versions 5.21.0 through 5.21.4
LXD versions 5.0.0 through 5.0.6
Description
An issue exists in the handling of project-restriction policies during snapshot restoration. An authenticated project operator in a restricted multi-tenant environment can bypass policy restrictions by importing a maliciously crafted instance backup that contains restricted configuration keys within a snapshot. These keys are applied to the live instance without policy validation upon restoration. Starting the modified instance allows the operator to obtain unauthorized host root access.
Recommendations
Update LXD to version 6.9 or later.
Update LXD to version 5.21.5 or later.
Update LXD to version 5.0.7 or later.
Exploit
Fix
LPE
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lxd