Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-63298: LXD NVIDIA Configuration Data Injection Risk
CVE-2026-63298 · published 22 days ago
Summary
An attacker with LXD access can inject malicious configuration, potentially allowing them to execute code on the host system. This risk exists when an authenticated user configures an NVIDIA instance within LXD. To mitigate this risk, ensure all users with LXD access are trustworthy, and consider implementing additional security measures to restrict configuration options.
What to do
- Update canonical lxd to version 5.0.8 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | canonical | lxd | < 5.0.8 |
| Debian:12 | debian | lxd | All versions |
| Debian:13 | debian | lxd | All versions |
Original advisory text
An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supply...
An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline characters within the 'nvidia.driver.capabilities' or 'nvidia.require.*' configuration values, an attacker can manipulate the generated lxc.conf file. This flaw enables the attacker to execute arbitrary code on the host system with the privileges of the LXD daemon.
References
- https://github.com/canonical/lxd/security/advisories/GHSA-vfh7-q59q-54v2 vdb-entry vendor-advisory
- https://security-tracker.debian.org/tracker/CVE-2026-63298 Vendor Advisory
Severity
9.9
Critical
CVSS 3.1: 8.7 (MITRE)
CVSS 3.1: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-78OS Command Injection
Timeline
Published12 Aug 2026
Updated30 Aug 2026
First seen12 Aug 2026
Monitor software like this
Free during beta