LXD是Canonical开源的一款基于Linux系统用于管理应用程序的容器。 LXD 6.8之前版本存在安全漏洞,该漏洞源于备份导入路径仅验证备份存档中的backup/index.yaml文件,而未对backup/container/backup.yaml文件进行项目限制检查,可能导致经过身份验证的远程攻击者绕过所有项目限制,完全控制主机。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-34179 | 9.1 CRITICAL | Update of type field in restricted TLS certificate allows privilege escalation to cluster |
| CVE-2026-34177 | 9.1 CRITICAL | VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf |
| CVE-2025-15480 | Senstive information disclosure was affecting ubuntu-desktop-provision | |
| CVE-2025-14551 | Senstive information disclosure was affecting subiquity |
No comments yet