Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-63297: LXD Security: Unauthorized Instance Copy in Restricted Projects
CVE-2026-63297 · published 22 days ago
Summary
An attacker with valid access can copy instances into projects with tighter security controls. This could allow them to gain more privileges or access sensitive data. To mitigate this risk, ensure all instance configurations are properly validated and restricted access is enforced.
What to do
- Update canonical lxd to version 5.0.8 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | canonical | lxd | < 5.0.8 |
| Debian:12 | debian | lxd | All versions |
| Debian:13 | debian | lxd | All versions |
Original advisory text
An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance c...
An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a target project, LXD performs restriction checks before configuration merging is complete, creating a time-of-check to time-of-use (TOCTOU) condition. An attacker can exploit this flaw to copy instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.
References
- https://github.com/canonical/lxd/security/advisories/GHSA-v989-qw7w-xvg4 vdb-entry vendor-advisory
- https://security-tracker.debian.org/tracker/CVE-2026-63297 Vendor Advisory
Severity
9.9
Critical
CVSS 3.1: 9.9 (MITRE)
CVSS 3.1: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-367Time-of-check Time-of-use (TOCTOU) Race Condition
CWE-863Incorrect Authorization
Timeline
Published12 Aug 2026
Updated24 Aug 2026
First seen12 Aug 2026
Monitor software like this
Free during beta