PT-2026-31596 · Canonical+1 · Lxd+1
Miha Purg
·
Published
2026-04-09
·
Updated
2026-05-13
·
CVE-2026-34178
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Canonical LXD versions prior to 6.8
Description
Canonical LXD versions prior to 6.8 have an issue where the backup import path validates project restrictions against
backup/index.yaml within a supplied tar archive, but instance creation is based on backup/container/backup.yaml, which is not subject to the same project restrictions. This allows an authenticated remote attacker with instance creation permissions in a restricted project to bypass project restrictions by crafting a malicious backup archive where backup.yaml contains restricted settings, such as security.privileged=true or raw.lxc directives, potentially leading to full host compromise.Recommendations
Update to version 6.8 or later.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lxd
Red Os