PT-2025-40332 · Canonical+2 · Lxd+2

Published

2025-10-02

·

Updated

2025-11-17

·

CVE-2025-54289

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Canonical LXD versions prior to 6.5 Canonical LXD version 5.21 through 5.21.4
Description A privilege escalation issue exists in the operations API of Canonical LXD. An attacker with read permissions can hijack terminal or console sessions and execute arbitrary commands. This is achieved by exploiting WebSocket connection hijacking format, utilizing secret values obtained from the operations API. The attacker needs to obtain secret values used for WebSocket connections when retrieving information about running operations. Successful attacks require specific timing, where the attacker hijacks the WebSocket connection while a victim with higher privileges has an active terminal or console session. The risk is considered relatively low due to the critical timing requirements. The issue is addressed by excluding WebSocket connection secret information from operations API responses for read-only users.
Recommendations Update to LXD version 6.5 or later. Update to LXD version 5.21.4 or later.

Exploit

Fix

LPE

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-54289
DSA-6027-1
GHSA-3G72-CHJ4-2228
GO-2025-3999
OPENSUSE-SU-2025:15710-1

Affected Products

Debian
Lxd
Red Os