Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-85185— Path traversal in LXD btrfs storage driver allows arbitrary file deletion and write on host as root

Quick assessment

Affected
Canonical LXD
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Canonical LXD 版本 4.0.2 及更高版本中 btrfs 存储驱动存在路径遍历漏洞(已在 4.0.14、5.0.10、5.21.8 和 6.10 版本中修复)。在 Linux 系统上,拥有在项目内创建实例权限的已认证客户端可以利用此漏洞以 root 权限删除主机上的任意文件。如果主机的根文件系统为 btrfs,攻击者还可以将受控内容写入主机的任意路径,从而导致主机被完全控制。攻击者通过构造包含 "../" 序列的子卷路径来实现此攻击,该路径可通过以下两种方式之一发送:一是在优化版 btrfs 备份的

CVSS 9.6 · Critical
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-85185

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Path traversal in LXD btrfs storage driver allows arbitrary file deletion and write on host as root
Source: CVE Program / CVE List V5
Vulnerability Description
Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete arbitrary files on the host as root. On hosts whose root filesystem is btrfs, the client can also place attacker-controlled content at arbitrary host paths, leading to full host compromise. The client does this with a crafted subvolume path containing ../ sequences, sent in either of two ways: in the optimized_header.yaml of an optimized btrfs backup, or in the btrfs migration header sent by a malicious migration source.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Canonical LXD 4.0.2 ~ 4.0.14 -

II. Public POCs for CVE-2026-85185

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-85185

请登录查看更多情报信息。

Other References for CVE-2026-85185 (1)

Same Patch Batch · Canonical · 2026-09-28 · 7 CVEs total

CVE-2026-87799 9.9 CRITICAL Arbitrary file write on LXD host via symlink in migration stream
CVE-2026-85526 9.9 CRITICAL Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipula
CVE-2026-97335 7.7 HIGH Incorrect authorization in LXD storage volume API allows reading volumes from other projec
CVE-2026-86335 6.3 MEDIUM LXD Cross-Project Private Image Theft via Unsanitized GetImageFromAnyProject Local Reuse
CVE-2026-87798 5.8 MEDIUM LXD client recursive file pull allows directory escape via malicious VM agent
CVE-2026-86334 4.2 MEDIUM CLI Path Traversal via Content-Disposition in LXD Image Export/Copy

IV. Related Vulnerabilities

V. Comments for CVE-2026-85185

No comments yet


Leave a comment