Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-63294: LXD Image Backup Vulnerability: Root Access via Malicious Archive
CVE-2026-63294 · published 22 days ago
Summary
An attacker can exploit a weakness in LXD's image import process to gain root access on a system. This happens when a malicious image archive contains a specially crafted backup file. To protect your system, ensure you only import images from trusted sources and keep your LXD installation up to date.
What to do
- Update canonical lxd to version 4.0.12 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | canonical | lxd | < 4.0.12 |
| Debian:12 | debian | lxd | All versions |
| Debian:13 | debian | lxd | All versions |
Original advisory text
A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to prope...
A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and confine the backup.yaml file when it exists as a symbolic link. An attacker can exploit this flaw by providing a malicious archive with a symlinked backup.yaml file, causing LXD to process unconfined configuration metadata and execute arbitrary commands with root privileges.
References
- https://github.com/canonical/lxd/security/advisories/GHSA-fv82-v4fj-mm4m vdb-entry vendor-advisory
- https://security-tracker.debian.org/tracker/CVE-2026-63294 Vendor Advisory
Severity
9.9
Critical
CVSS 3.1: 9.9 (MITRE)
CVSS 3.1: 9.9 (OSV)
Exploitation
EPSS 1%
Type
CWE-59Link Following
Timeline
Published12 Aug 2026
Updated30 Aug 2026
First seen13 Aug 2026
Monitor software like this
Free during beta