Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.6

CVE-2026-85185: LXD btrfs storage allows host file delete or write

CVE-2026-85185 · published 12 days ago
Summary

If you run LXD (or its Debian fork Incus) on a Linux system that uses the btrfs file system, a user who is allowed to create containers could delete any file on the host or place their own files anywhere, effectively taking control of the server. The issue is fixed in newer releases, so upgrade LXD/Incus to the latest version and limit container‑creation rights to trusted users.

What to do
  • Update debian incus to version 6.0.4-2+deb13u11.
  • Update debian incus to version 6.0.4-2+deb13u1.
  • Update debian incus to version 7.0.1-5.
  • Update canonical lxd to version 4.0.14 or later.
Affected software
Ecosystem VendorProductAffected versions
– canonical lxd < 4.0.14
Debian:13 debian incus < 6.0.4-2+deb13u11
< 6.0.4-2+deb13u1
Fix: upgrade to 6.0.4-2+deb13u11
Debian:14 debian incus < 7.0.1-5
Fix: upgrade to 7.0.1-5
Debian:12 debian lxd All versions
Ubuntu:Pro:16.04:LTS canonical lxd All versions
Ubuntu:Pro:24.04:LTS canonical incus All versions
Original advisory text
Path traversal in LXD btrfs storage driver allows arbitrary file deletion and write on host as root
Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete arbitrary files on the host as root. On hosts whose root filesystem is btrfs, the client can also place attacker-controlled content at arbitrary host paths, leading to full host compromise. The client does this with a crafted subvolume path containing ../ sequences, sent in either of two ways: in the optimized_header.yaml of an optimized btrfs backup, or in the btrfs migration header sent by a malicious migration source.
Fix within
Internet-facing 60 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker partial control
Severity
9.6 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-22Path Traversal
Timeline
Published28 Sep 2026
Updated9 Oct 2026
First seen28 Sep 2026
Track software like this
Free during beta