Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-85526: LXD backup import lets privileged user alter host files
CVE-2026-85526 · published 12 days ago
Summary
When LXD (or its Debian variants) imports a Btrfs backup, a user who can create containers can craft a special file path that lets them delete or replace any file on the server as the root user. This occurs because the program does not properly check the path it is given. Limit the ability to create containers to trusted users and apply the latest updates that fix the check.
What to do
- Update debian incus to version 6.0.4-2+deb13u11.
- Update debian incus to version 6.0.4-2+deb13u1.
- Update debian incus to version 7.0.1-5.
- Update canonical lxd to version 4.0.14 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | canonical | lxd | < 4.0.14 |
| Debian:13 | debian | incus |
< 6.0.4-2+deb13u11 < 6.0.4-2+deb13u1 Fix: upgrade to 6.0.4-2+deb13u11
|
| Debian:14 | debian | incus |
< 7.0.1-5 Fix: upgrade to 7.0.1-5
|
| Debian:12 | debian | lxd | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | lxd | All versions |
| Ubuntu:Pro:24.04:LTS | canonical | incus | All versions |
Original advisory text
Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipulation in LXD
Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root via a crafted subvolumes[].path entry in backup/optimized_header.yaml during a btrfs optimized backup import.
References
- https://github.com/canonical/lxd/security/advisories/GHSA-h85r-gjgx-g2rv Third Party Advisory
- https://github.com/canonical/lxd-private/pull/103 Patch
- https://security-tracker.debian.org/tracker/CVE-2026-85526 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85526... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-85526 Vendor Advisory
- https://github.com/canonical/lxd Product
- https://ubuntu.com/security/CVE-2026-85526 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-85526 Third Party Advisory
- https://github.com/canonical/lxd-private/pull/104 Patch
- https://github.com/canonical/lxd-private/pull/105 Patch
- https://github.com/canonical/lxd-private/pull/84 Patch
- https://github.com/canonical/lxd-private/pull/87 Patch
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-22Path Traversal
Timeline
Published28 Sep 2026
Updated9 Oct 2026
First seen28 Sep 2026
Sources
CVE-2026-85526 · NVD
CVE-2026-85526 · MITRE
DEBIAN-CVE-2026-85526 · OSV
UBUNTU-CVE-2026-85526 · OSV
CVE-2026-85526 · OSV
GHSA-h85r-gjgx-g2rv · GHSA
Track software like this
Free during beta