Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-85526: LXD backup import lets privileged user alter host files

CVE-2026-85526 · published 12 days ago
Summary

When LXD (or its Debian variants) imports a Btrfs backup, a user who can create containers can craft a special file path that lets them delete or replace any file on the server as the root user. This occurs because the program does not properly check the path it is given. Limit the ability to create containers to trusted users and apply the latest updates that fix the check.

What to do
  • Update debian incus to version 6.0.4-2+deb13u11.
  • Update debian incus to version 6.0.4-2+deb13u1.
  • Update debian incus to version 7.0.1-5.
  • Update canonical lxd to version 4.0.14 or later.
Affected software
Ecosystem VendorProductAffected versions
– canonical lxd < 4.0.14
Debian:13 debian incus < 6.0.4-2+deb13u11
< 6.0.4-2+deb13u1
Fix: upgrade to 6.0.4-2+deb13u11
Debian:14 debian incus < 7.0.1-5
Fix: upgrade to 7.0.1-5
Debian:12 debian lxd All versions
Ubuntu:Pro:16.04:LTS canonical lxd All versions
Ubuntu:Pro:24.04:LTS canonical incus All versions
Original advisory text
Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipulation in LXD
Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root via a crafted subvolumes[].path entry in backup/optimized_header.yaml during a btrfs optimized backup import.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.9 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-22Path Traversal
Timeline
Published28 Sep 2026
Updated9 Oct 2026
First seen28 Sep 2026
Track software like this
Free during beta