Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-63293: LXD: Untrusted Image Can Read/Write Host Files as Root
CVE-2026-63293 · published 22 days ago
Summary
LXD, a Linux container manager, has a vulnerability that allows an attacker to access and modify files on the host system by importing a specially crafted image. This could lead to unauthorized data access or modification. To protect your system, ensure you only import images from trusted sources.
What to do
- Update canonical lxd to version 4.0.12 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:12 | debian | lxd | All versions |
| Debian:13 | debian | lxd | All versions |
| – | canonical | lxd | < 4.0.12 |
Original advisory text
A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate ...
A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate whether the metadata.yaml file is a symbolic link. An attacker can exploit this flaw by providing a crafted image archive with a symlinked metadata.yaml file pointing to target file paths on the host system.
References
- https://github.com/canonical/lxd/security/advisories/GHSA-j825-cg34-5fr5 vdb-entry vendor-advisory
- https://security-tracker.debian.org/tracker/CVE-2026-63293 Vendor Advisory
Severity
9.9
Critical
CVSS 3.1: 9.9 (MITRE)
CVSS 3.1: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-59Link Following
Timeline
Published12 Aug 2026
Updated30 Aug 2026
First seen13 Aug 2026
Monitor software like this
Free during beta