Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.6
CVE-2026-85185: LXD btrfs storage allows host file delete or write
CVE-2026-85185 · published 12 days ago
Summary
If you run LXD (or its Debian fork Incus) on a Linux system that uses the btrfs file system, a user who is allowed to create containers could delete any file on the host or place their own files anywhere, effectively taking control of the server. The issue is fixed in newer releases, so upgrade LXD/Incus to the latest version and limit container‑creation rights to trusted users.
What to do
- Update debian incus to version 6.0.4-2+deb13u11.
- Update debian incus to version 6.0.4-2+deb13u1.
- Update debian incus to version 7.0.1-5.
- Update canonical lxd to version 4.0.14 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | canonical | lxd | < 4.0.14 |
| Debian:13 | debian | incus |
< 6.0.4-2+deb13u11 < 6.0.4-2+deb13u1 Fix: upgrade to 6.0.4-2+deb13u11
|
| Debian:14 | debian | incus |
< 7.0.1-5 Fix: upgrade to 7.0.1-5
|
| Debian:12 | debian | lxd | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | lxd | All versions |
| Ubuntu:Pro:24.04:LTS | canonical | incus | All versions |
Original advisory text
Path traversal in LXD btrfs storage driver allows arbitrary file deletion and write on host as root
Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete arbitrary files on the host as root. On hosts whose root filesystem is btrfs, the client can also place attacker-controlled content at arbitrary host paths, leading to full host compromise. The client does this with a crafted subvolume path containing ../ sequences, sent in either of two ways: in the optimized_header.yaml of an optimized btrfs backup, or in the btrfs migration header sent by a malicious migration source.
References
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85185... Vendor Advisory
- https://github.com/canonical/lxd Product
- https://nvd.nist.gov/vuln/detail/CVE-2026-85185 Vendor Advisory
- https://github.com/canonical/lxd/security/advisories/GHSA-27q7-qwhm-c34p Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-85185 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-85185 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-85185 Third Party Advisory
Internet-facing
60 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker partial control
Type
CWE-22Path Traversal
Timeline
Published28 Sep 2026
Updated9 Oct 2026
First seen28 Sep 2026
Sources
CVE-2026-85185 · NVD
CVE-2026-85185 · MITRE
DEBIAN-CVE-2026-85185 · OSV
CVE-2026-85185 · OSV
GHSA-27q7-qwhm-c34p · GHSA
UBUNTU-CVE-2026-85185 · OSV
Track software like this
Free during beta