Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-63298: LXD NVIDIA Configuration Data Injection Risk

CVE-2026-63298 · published 22 days ago
Summary

An attacker with LXD access can inject malicious configuration, potentially allowing them to execute code on the host system. This risk exists when an authenticated user configures an NVIDIA instance within LXD. To mitigate this risk, ensure all users with LXD access are trustworthy, and consider implementing additional security measures to restrict configuration options.

What to do
  • Update canonical lxd to version 5.0.8 or later.
Affected software
Ecosystem VendorProductAffected versions
– canonical lxd < 5.0.8
Debian:12 debian lxd All versions
Debian:13 debian lxd All versions
Original advisory text
An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supply...
An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline characters within the 'nvidia.driver.capabilities' or 'nvidia.require.*' configuration values, an attacker can manipulate the generated lxc.conf file. This flaw enables the attacker to execute arbitrary code on the host system with the privileges of the LXD daemon.
Severity
9.9 Critical
CVSS 3.1: 8.7 (MITRE)
CVSS 3.1: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-78OS Command Injection
Timeline
Published12 Aug 2026
Updated30 Aug 2026
First seen12 Aug 2026
Sources
CVE-2026-63298 · MITRE
Monitor software like this
Free during beta