Canonical LXD是英国Canonical公司开源的一款基于Linux系统用于管理应用程序的容器。 Canonical LXD存在异常处理不当漏洞,该漏洞源于在CreateCustomVolumeFromBackup中存在空指针取消引用问题,可能导致具有can_create_storage_volumes权限的已认证用户通过特制的自定义卷备份tarball(省略expires_at快照字段)造成拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12411 | 8.4 HIGH | Broken Access Control in Canonical LXD DevLXD API |
| CVE-2026-9640 | 7.2 HIGH | LXD Snapshot Import Privilege Escalation Vulnerability |
| CVE-2026-28385 | 5.0 MEDIUM | SSRF via image import from URL allows internal network probing by authenticated users |
No comments yet