Skip to main content

Vendor/product archive

canonical / lxd CVEs

Beta · best-effort

22 CVEs tagged to canonical / lxd3 Critical, 6 High, 10 Medium, 3 Low, 0 Unrated.

CVE-2026-28385

Published Jun 26, 2026

In Canonical LXD versions 4.12 through 6.9, a Server-Side Request Forgery (SSRF) vulnerability in the image import functionality allows authenticated users with the can_create_ima…

CVSS 5.0 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-9640

Published Jun 26, 2026

A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies during…

CVSS 7.2 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-9639

Published Jun 26, 2026

Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to caus…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-12411

Published Jun 26, 2026

Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume vi…

CVSS 8.4 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-34179

Published Apr 9, 2026

In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PUT/PATCH requests to /1.0/certi…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-34178

Published Apr 9, 2026

In Canonical LXD before 6.8, the backup import path validates project restrictions against backup/index.yaml in the supplied tar archive but creates the instance from backup/conta…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-34177

Published Apr 9, 2026

Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limits/permissions.go), which omits raw.apparmor and raw.qemu.co…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-3351

Published Mar 3, 2026

Improper authorization in the API endpoint GET /1.0/certificates in Canonical LXD 6.6 on Linux allows an authenticated, restricted user to enumerate all certificate fingerprints t…

CVSS 2.1 · Low
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-54293

Published Oct 2, 2025

Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attackers to read arbitrary files on the host system via crafted lo…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54292

Published Oct 2, 2025

Path traversal in Canonical LXD LXD-UI versions before 6.5 and 5.21.4 on all platforms allows remote authenticated attackers to access or modify unintended resources via crafted r…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54291

Published Oct 2, 2025

Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remote attackers to determine project existence via differing H…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54290

Published Oct 2, 2025

Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence without authentication via craft…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54289

Published Oct 2, 2025

Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read permissions to hijack terminal or console sessions and execute arbitra…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54288

Published Oct 2, 2025

Information Spoofing in devLXD Server in Canonical LXD versions 4.0 and above on Linux container platforms allows attackers with root privileges within any container to impersonat…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54287

Published Oct 2, 2025

Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance configuration permissions to read arbitrary files on the hos…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54286

Published Oct 2, 2025

Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances without user consent via crafted H…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6219

Published Dec 6, 2024

Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-6156

Published Dec 6, 2024

Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-49721

Published Feb 14, 2024

An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1582

Published Jun 9, 2016

LXD before 2.0.2 does not properly set permissions when switching an unprivileged container into privileged mode, which allows local users to access arbitrary world readable paths…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1581

Published Jun 9, 2016

LXD before 2.0.2 uses world-readable permissions for /var/lib/lxd/zfs.img when setting up a loop based ZFS pool, which allows local users to copy and read data from arbitrary cont…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-22 of 22 CVEsPage 1 of 1