Canonical
Canonical LXD: vulnerabilidades y CVE
Canonical LXD tiene 42 vulnerabilidades publicadas, 36 de ellas en los últimos 12 meses. 18 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE42
Últimos 12 meses36
Críticas18
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-97335 | Alta (7.7) | 0.21% | — | 28 sept 2026 | Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create… |
| CVE-2026-87799 | Crítica (9.9) | 0.41% | — | 28 sept 2026 | Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom… |
| CVE-2026-87798 | Media (5.8) | 0.19% | — | 28 sept 2026 | Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.0.2 up to 6.9 (fixed in 4.0.14, 5.0.10 and 5.21.8) on Linux allows an attacker with root access inside a… |
| CVE-2026-86335 | Media (6.3) | 0.22% | — | 28 sept 2026 | Missing Authorization in imageDownload in Canonical LXD before 5.0.10, 5.21.8, and 6.10 on Linux allows a project-restricted client to access private images from other projects via local fingerprint reuse during image… |
| CVE-2026-86334 | Media (4.2) | 0.34% | — | 28 sept 2026 | Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms allows a remote malicious or machine-in-the-middle image server… |
| CVE-2026-85526 | Crítica (9.9) | 0.52% | — | 28 sept 2026 | Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host… |
| CVE-2026-85185 | Crítica (9.6) | 0.36% | — | 28 sept 2026 | Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to… |
| CVE-2026-66897 | Crítica (9.9) | 0.72% | — | 24 ago 2026 | A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root.… |
| CVE-2026-66898 | Crítica (9.9) | 0.59% | — | 12 ago 2026 | A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and… |
| CVE-2026-16033 | Alta (8.5) | 0.35% | — | 12 ago 2026 | A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template… |
| CVE-2026-63300 | Crítica (9.9) | 0.54% | — | 12 ago 2026 | An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass… |
| CVE-2026-63299 | Crítica (9.9) | 0.59% | — | 12 ago 2026 | An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource limits during volume operations: the… |
| CVE-2026-63298 | Crítica (9.9) | 0.69% | — | 12 ago 2026 | An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline characters… |
| CVE-2026-63297 | Crítica (9.9) | 0.34% | — | 12 ago 2026 | An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an… |
| CVE-2026-63296 | Crítica (9.9) | 0.44% | — | 12 ago 2026 | An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration… |
| CVE-2026-63295 | Media (4.3) | 0.35% | — | 12 ago 2026 | An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions. When a project is configured with restrictions on container privileges (such as… |
| CVE-2026-63294 | Crítica (9.9) | 0.88% | — | 12 ago 2026 | A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and… |
| CVE-2026-63293 | Crítica (9.9) | 0.59% | — | 12 ago 2026 | A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate whether the… |
| CVE-2026-62420 | Crítica (9.9) | 0.54% | — | 12 ago 2026 | An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different… |
| CVE-2026-28385 | Media (5) | 0.28% | — | 26 jun 2026 | In Canonical LXD versions 4.12 through 6.9, a Server-Side Request Forgery (SSRF) vulnerability in the image import functionality allows authenticated users with the can_create_images entitlement to interact with… |
| CVE-2026-9640 | Alta (7.2) | 0.63% | — | 26 jun 2026 | A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies during snapshot restoration.. An authenticated… |
| CVE-2026-9639 | Media (6.5) | 0.55% | — | 26 jun 2026 | Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially… |
| CVE-2026-12411 | Crítica (9.6) | 0.29% | — | 26 jun 2026 | Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over… |
| CVE-2026-34179 | Crítica (9.1) | 0.42% | — | 9 abr 2026 | In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PUT/PATCH requests to /1.0/certificates/{fingerprint} for restricted TLS… |
| CVE-2026-34178 | Crítica (9.1) | 0.68% | — | 9 abr 2026 | In Canonical LXD before 6.8, the backup import path validates project restrictions against backup/index.yaml in the supplied tar archive but creates the instance from backup/container/backup.yaml, a separate file in the… |
| CVE-2026-34177 | Crítica (9.1) | 0.61% | — | 9 abr 2026 | Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limits/permissions.go), which omits raw.apparmor and raw.qemu.conf from the set of keys blocked under… |
| CVE-2026-28384 | Crítica (9.4) | 0.86% | — | 12 mar 2026 | An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup… |
| CVE-2026-3351 | Baja (2.1) | 0.22% | — | 3 mar 2026 | Improper authorization in the API endpoint GET /1.0/certificates in Canonical LXD 6.6 on Linux allows an authenticated, restricted user to enumerate all certificate fingerprints trusted by the lxd server. |
| CVE-2025-54293 | Alta (7.1) | 0.58% | — | 2 oct 2025 | Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attackers to read arbitrary files on the host system via crafted log file names or symbolic links. |
| CVE-2025-54292 | Media (4.8) | 0.32% | — | 2 oct 2025 | Path traversal in Canonical LXD LXD-UI versions before 6.5 and 5.21.4 on all platforms allows remote authenticated attackers to access or modify unintended resources via crafted resource names embedded in URL paths. |