Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

lxd — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in lxd, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of common vulnerabilities and exposures associated with LXD, the container management system developed by Canonical. It serves as a centralized resource for security professionals and system administrators seeking detailed insights into the safety and integrity of this widely used Linux container runtime. The content collected on this page encompasses a broad spectrum of security issues, ranging from privilege escalation flaws and container breakout vulnerabilities to information disclosure and denial of service weaknesses. The data covers a significant historical period, ensuring that both recent patches and legacy issues are accounted for, thereby providing a complete picture of the product's security posture over time. Here, users can track vendor advisories from Canonical to understand the context and severity of reported issues. Additionally, the page allows for a deeper understanding of specific weakness classes, such as how misconfigurations or code errors might be exploited within the LXD architecture. Readers can also look up the complete vulnerability history of LXD products to identify trends, assess long-term risks, and compare the evolution of security fixes across different versions. This structured approach facilitates efficient risk management and helps organizations prioritize remediation efforts based on comprehensive, historical data rather than isolated incident reports. By consolidating these details, the page aims to enhance transparency and support informed decision-making regarding the deployment and maintenance of LXD environments in enterprise and cloud settings.

Vendor: Ubuntu

CVE IDTitleCVSSSeverityPublished
CVE-2026-34179 Update of type field in restricted TLS certificate allows privilege escalation to cluster admin CWE-915 9.1 Critical2026-04-09
CVE-2026-34178 Importing a crafted backup leads to project restriction bypass CWE-20 9.1 Critical2026-04-09
CVE-2026-34177 VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf CWE-184 9.1 Critical2026-04-09
CVE-2026-28384 Authenticated RCE via unsanitized compression_algorithm CWE-78 8.8AIHighAI2026-03-12
CVE-2026-3351 Authorization Bypass in LXD GET /1.0/certificates Endpoint CWE-862 4.3AIMediumAI2026-03-03
CVE-2025-54293 Path Traversal in LXD Instance Log File Retrieval CWE-22 6.5AIMediumAI2025-10-02
CVE-2025-54292 Client-Side Path Traversal in LXD-UI CWE-22 8.1AIHighAI2025-10-02
CVE-2025-54291 Project existence disclosure in LXD images API CWE-209 5.3AIMediumAI2025-10-02
CVE-2025-54290 Project Existence Disclosure via Error Handling in LXD Image Export CWE-200 5.3AIMediumAI2025-10-02
CVE-2025-54289 Privilege Escalation via WebSocket Connection Hijacking in LXD Operations API CWE-1385 8.8AIHighAI2025-10-02
CVE-2025-54288 Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server CWE-290 5.1AIMediumAI2025-10-02
CVE-2025-54287 Arbitrary File Read via Template Injection in Snapshot Patterns CWE-1336 6.5AIMediumAI2025-10-02
CVE-2025-54286 CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI CWE-352 8.8AIHighAI2025-10-02
CVE-2024-6219 LXD 安全漏洞 3.8 Low2024-12-05
CVE-2024-6156 LXD 安全漏洞 3.8 Low2024-12-05
CVE-2023-49721 EDK2 安全漏洞 6.7 Medium2024-02-14
CVE-2015-1340 chmod race in doUidshiftIntoContainer 8.1 -2019-04-22

All 17 known CVE vulnerabilities affecting lxd with full Chinese analysis, references, and POCs where available.