All CVEs
Vulnerability intelligence

CVE-2026-85526

Canonical LXD CWE-22

Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root via a crafted subvolumes[].path entry in backup/optimized_header.yaml during a btrfs optimized backup import.

CVSS Score
9.9
Critical
EPSS — Exploit Probability
—
Awaiting FIRST.org data · checked 2026-09-29
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
Patch available
Vendor fix published
NVD entry Vendor patch PoC / advisory

1 article across 1 outlet · first covered Sep 29, 2026 · latest Sep 29, 2026

Coverage timeline

Related CVEs — Canonical