Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-87799— Arbitrary file write on LXD host via symlink in migration stream

Quick assessment

Affected
Canonical LXD
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Canonical LXD 4.0 及更高版本在 Linux 上的迁移接收路径中存在链接解析不当漏洞(已在 4.0.14、5.0.10、5.21.8 和 6.10 版本中修复)。拥有在某个项目中创建实例或自定义存储卷权限的已认证客户端,或恶意的迁移源服务器,可以利用此漏洞将攻击者控制的文件写入目标主机的任意路径,且以 root 用户权限执行,从而导致目标主机被完全攻陷。攻击者通过构造特殊的 rsync 或 btrfs 发送流,在传输的卷(如 rootfs 或 root.img)中植入符号链接,随后通过该符号链接写入

CVSS 9.9 · Critical
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-87799

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Arbitrary file write on LXD host via symlink in migration stream
Source: CVE Program / CVE List V5
Vulnerability Description
Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes in a project, or a malicious migration source server, to write attacker-controlled files to arbitrary paths on the target host as root, leading to full host compromise. The attacker does this with a crafted rsync or btrfs send stream that plants a symlink in the transferred volume, such as rootfs or root.img, and then writes through it.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
在文件访问前对链接解析不恰当(链接跟随)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Canonical LXD 4.0.0 ~ 4.0.14 -

II. Public POCs for CVE-2026-87799

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-87799

请登录查看更多情报信息。

Other References for CVE-2026-87799 (1)

Same Patch Batch · Canonical · 2026-09-28 · 7 CVEs total

CVE-2026-85526 9.9 CRITICAL Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipula
CVE-2026-85185 9.6 CRITICAL Path traversal in LXD btrfs storage driver allows arbitrary file deletion and write on hos
CVE-2026-97335 7.7 HIGH Incorrect authorization in LXD storage volume API allows reading volumes from other projec
CVE-2026-86335 6.3 MEDIUM LXD Cross-Project Private Image Theft via Unsanitized GetImageFromAnyProject Local Reuse
CVE-2026-87798 5.8 MEDIUM LXD client recursive file pull allows directory escape via malicious VM agent
CVE-2026-86334 4.2 MEDIUM CLI Path Traversal via Content-Disposition in LXD Image Export/Copy

IV. Related Vulnerabilities

V. Comments for CVE-2026-87799

No comments yet


Leave a comment