Canonical LXD是英国Canonical公司开源的一款基于Linux系统用于管理应用程序的容器。 Canonical LXD 5.0.0版本至5.0.8之前版本、5.21.0版本至5.21.6之前版本和4.0.0版本至4.0.12之前版本存在命令注入漏洞,该漏洞源于NVIDIA实例配置处理中对特殊元素中和不当,经过身份验证的攻击者可通过在'nvidia.driver.capabilities'或'nvidia.require.*'配置值中注入换行字符来操纵生成的lxc.conf文件,从而以LXD
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-62420 | 9.9 CRITICAL | Cross-project cluster migration bypasses project restrictions via cluster notification fla |
| CVE-2026-63300 | 9.9 CRITICAL | Cross-project instance move bypasses all project restrictions allowing host command execut |
| CVE-2026-63296 | 9.9 CRITICAL | Project restriction bypass via instance migration config override |
| CVE-2026-63293 | 9.9 CRITICAL | Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as |
| CVE-2026-63294 | 9.9 CRITICAL | Root RCE via image backup.yaml symlink |
| CVE-2026-63297 | 9.9 CRITICAL | Cross-project instance copy bypasses target project restrictions via TOCTOU in config merg |
| CVE-2026-66898 | 9.9 CRITICAL | Path traversal via unvalidated instance name in backup tarball restore enables root file w |
| CVE-2026-63299 | 8.5 HIGH | Storage volume cross-project move and snapshot restore bypass project disk limits |
| CVE-2026-16033 | 8.5 HIGH | Arbitrary file read+write on host via templates/ symlink in malicious image |
| CVE-2026-63295 | 4.3 MEDIUM | Project restriction `restricted.containers.privilege=isolated` bypassable by omitting `sec |
No comments yet