All 40 CVE vulnerabilities found in LXD, with AI-generated Chinese analysis, references, and POCs.
This page aggregates security vulnerabilities for LXD, a container management system developed by Canonical. It collects disclosed flaws in the LXD product and its related Linux containers, covering historical advisories from 2016 through the present. Readers can use this view to track the vendor's advisory history, analyze common weakness types affecting LXD, and review the overall vulnerability timeline for this specific container runtime. The dataset includes critical, high, and medium severity issues, organized to facilitate rapid assessment of risk exposure and patching priority.
Vendor: Ubuntu
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-54291 | Project existence disclosure in LXD images API CWE-209 | 5.3AI | Medium AI | 2025-10-02 |
| CVE-2025-54290 | Project Existence Disclosure via Error Handling in LXD Image Export CWE-200 | 5.3AI | Medium AI | 2025-10-02 |
| CVE-2025-54289 | Privilege Escalation via WebSocket Connection Hijacking in LXD Operations API CWE-1385 | 8.8AI | High AI | 2025-10-02 |
| CVE-2025-54288 | Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server CWE-290 | 5.1AI | Medium AI | 2025-10-02 |
| CVE-2025-54287 | Arbitrary File Read via Template Injection in Snapshot Patterns CWE-1336 | 6.5AI | Medium AI | 2025-10-02 |
| CVE-2025-54286 | CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI CWE-352 | 8.8AI | High AI | 2025-10-02 |
| CVE-2024-6219 | LXD 安全漏洞 | 3.8 | Low | 2024-12-05 |
| CVE-2024-6156 | LXD 安全漏洞 | 3.8 | Low | 2024-12-05 |
| CVE-2023-49721 | EDK2 安全漏洞 | 6.7 | Medium | 2024-02-14 |
| CVE-2015-1340 | chmod race in doUidshiftIntoContainer | 8.1 | - | 2019-04-22 |
All 40 known CVE vulnerabilities affecting LXD with full Chinese analysis, references, and POCs where available.