Canonical LXD是英国Canonical公司开源的一款基于Linux系统用于管理应用程序的容器。 Canonical LXD 4.0.0至4.0.12之前版本、5.0.0至5.0.8之前版本、5.21.0至5.21.6之前版本和6.0至6.10之前版本存在后置链接漏洞,该漏洞源于在处理特制镜像或备份归档的导入或解压过程中,未正确验证和限制backup.yaml符号链接,导致处理未受限制的配置元数据,攻击者可利用恶意归档中的符号链接backup.yaml文件以root权限执行任意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-62420 | 9.9 CRITICAL | Cross-project cluster migration bypasses project restrictions via cluster notification fla |
| CVE-2026-63300 | 9.9 CRITICAL | Cross-project instance move bypasses all project restrictions allowing host command execut |
| CVE-2026-63296 | 9.9 CRITICAL | Project restriction bypass via instance migration config override |
| CVE-2026-63293 | 9.9 CRITICAL | Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as |
| CVE-2026-63297 | 9.9 CRITICAL | Cross-project instance copy bypasses target project restrictions via TOCTOU in config merg |
| CVE-2026-66898 | 9.9 CRITICAL | Path traversal via unvalidated instance name in backup tarball restore enables root file w |
| CVE-2026-63298 | 8.7 HIGH | LXD arbitrary lxc.conf directive injection via NVIDIA instance configuration |
| CVE-2026-63299 | 8.5 HIGH | Storage volume cross-project move and snapshot restore bypass project disk limits |
| CVE-2026-16033 | 8.5 HIGH | Arbitrary file read+write on host via templates/ symlink in malicious image |
| CVE-2026-63295 | 4.3 MEDIUM | Project restriction `restricted.containers.privilege=isolated` bypassable by omitting `sec |
No comments yet