PT-2024-37461 · Canonical · Lxd

Markylaing

·

Published

2024-12-02

·

Updated

2025-11-13

·

CVE-2024-6219

CVSS v3.1

3.8

Low

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: LXD versions prior to 5.21.1
Description: A restricted certificate could be added to the trust store with its restrictions not honoured in LXD's PKI mode. This occurs when the core.trust ca certificates configuration option is disabled, causing restrictions applied to a certificate to be ignored due to the presence of a server.ca file in LXD DIR. The issue allows a client with a restricted certificate to have full access to LXD.
Recommendations: For versions prior to 5.21.1, update to version 5.21.1 or later to resolve the issue. As a temporary workaround, consider disabling the PKI mode or enabling the core.trust ca certificates configuration option to allow for passwordless PKI with CRL revocation. Restrict access to the trust store to minimize the risk of exploitation. Avoid adding restricted certificates to the trust store until the issue is resolved.

Fix

Improper Authentication

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2024-6219
GHSA-JPMC-7P9C-4RXF
GO-2024-3313
OPENSUSE-SU-2024:14567-1

Affected Products

Lxd