PT-2025-40333 · Canonical+2 · Lxd+2

Published

2025-10-02

·

Updated

2025-11-17

·

CVE-2025-54290

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Canonical LXD versions prior to 6.5 Canonical LXD versions prior to 5.21.4
Description An information disclosure issue exists in the image export API of Canonical LXD. A network attacker can determine project existence without authentication by sending crafted requests that utilize wildcard fingerprints. The issue affects systems running on Linux.
Recommendations Update to a version of Canonical LXD 6.5 or later. Update to a version of Canonical LXD 5.21.4 or later.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-54290
DSA-6027-1
GHSA-P3X5-MVMP-5F35
GO-2025-4002
OPENSUSE-SU-2025:15710-1

Affected Products

Debian
Lxd
Red Os