securityonline.info 29 Sept 2026, 02:09 UTC

Critical LXD Flaws Let Tenants Overwrite Host Files as Root

Critical LXD Flaws Let Tenants Overwrite Host Files as Root
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Available

CANONICAL has patched three critical vulnerabilities in LXD, its manager for system containers and virtual machines. CVE-2026-87799 and CVE-2026-85526 are rated CVSS 9.9, while CVE-2026-85185 is rated 9.6. The flaws can allow a low-privileged user, or a malicious migration source, to write to or delete files on the host as root. This could let one tenant compromise other workloads on a shared LXD system. The affected ranges are LXD 4.0 and later for CVE-2026-87799, and LXD 4.0.2 and later for the two btrfs issues.

CVE-2026-87799 abuses symlinks planted in migration data, causing rsync or btrfs receive to redirect later writes outside the intended volume; the advisory says optimised ZFS transfers are not affected. CVE-2026-85185 uses an unchecked btrfs subvolume path in backup and migration headers, while CVE-2026-85526 exploits path traversal in an optimised backup tarball restored to btrfs storage. Canonical’s advisories report no exploitation in the wild, although a public proof of concept has been confirmed.

Administrators should upgrade to LXD 4.0.14, 5.0.10, 5.21.8 or 6.10, or use the 6.9 build at commit `bf243da`. Until patching, access to instance and volume creation, migrations and btrfs backup imports should be restricted to trusted users and sources.

View full article

Article by CyberSIXT