Canonical LXD 的 CLI 客户端在 4.0.2 到 4.0.14 之前、5.0.10 之前、5.21.8 之前以及 6.10 之前版本中,其镜像导出和复制功能存在路径遍历漏洞,影响所有平台。该漏洞允许远程恶意镜像服务器或处于中间人位置的服务器,在统一镜像导出或复制操作指向本地目录目标时,通过精心构造的 Content-Disposition 响应头中的 filename 参数,覆盖任意本地文件,并在客户端系统上执行代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-87799 | 9.9 CRITICAL | Arbitrary file write on LXD host via symlink in migration stream |
| CVE-2026-85526 | 9.9 CRITICAL | Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipula |
| CVE-2026-85185 | 9.6 CRITICAL | Path traversal in LXD btrfs storage driver allows arbitrary file deletion and write on hos |
| CVE-2026-97335 | 7.7 HIGH | Incorrect authorization in LXD storage volume API allows reading volumes from other projec |
| CVE-2026-86335 | 6.3 MEDIUM | LXD Cross-Project Private Image Theft via Unsanitized GetImageFromAnyProject Local Reuse |
| CVE-2026-87798 | 5.8 MEDIUM | LXD client recursive file pull allows directory escape via malicious VM agent |
No comments yet