Canonical LXD是英国Canonical公司开源的一款基于Linux系统用于管理应用程序的容器。 LXD 6.0至6.9之前版本、5.21.0至5.21.5之前版本和5.0.0至5.0.7之前版本存在授权问题漏洞,该漏洞源于快照恢复期间的项目限制策略处理问题,可能导致身份验证的项目操作员在受限多租户环境中导入包含受限制配置密钥的恶意备份,恢复后密钥未经策略验证应用于实例,启动修改后实例可获取未授权的主机root访问权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-12411 | 8.4 HIGH | Broken Access Control in Canonical LXD DevLXD API |
| CVE-2026-9639 | 6.5 MEDIUM | Authenticated Denial of Service via Malicious Backup Tarball in LXD |
| CVE-2026-28385 | 5.0 MEDIUM | SSRF via image import from URL allows internal network probing by authenticated users |
No comments yet