CRITICAL🇵🇱 Wersja polska

CVE-2026-34178

CVSS 9.1v3.1pub. 2026-04-09upd. 2026-04-22

In Canonical LXD before 6.8, the backup import path validates project restrictions against backup/index.yaml in the supplied tar archive but creates the instance from backup/container/backup.yaml, a separate file in the same archive that is never checked against project restrictions. An authenticated remote attacker with instance-creation permission in a restricted project can craft a backup archive where backup.yaml carries restricted settings such as security.privileged=true or raw.lxc directives, bypassing all project restriction enforcement and allowing full host compromise.

🤖 AI Analysis
How it works

During import of a tar archive containing an LXD backup, project restriction validation is performed only based on the backup/index.yaml file. The backup/container/backup.yaml file — actually used for instance restoration — is never verified. An attacker can craft an archive where backup.yaml contains privileged settings, such as security.privileged=true or raw.lxc directives, which would normally be blocked by project restrictions. As a result, the instance is created with these disallowed settings, bypassing all project policy enforcement mechanisms.

Impact

An attacker can launch a privileged container instance with access to host resources, leading to full compromise of the host system — violations of confidentiality, integrity, and availability of data and infrastructure.

Mitigation & patch

Canonical LXD must be updated to version 6.8 or newer. Patch details are available in the pull request and in the vendor's security advisory at https://github.com/canonical/lxd/security/advisories/GHSA-q96j-3fmm-7fv4

Who is affected

Canonical LXD in versions earlier than 6.8

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Canonical Lxd

    APP
    Canonical
    4.12 – 5.0.65.21.0 – 5.21.46.0 – 6.7
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Container
CWE
References

Related vulnerabilities

CVE-2026-34177CRITICAL9.1PL ✓same product

Canonical LXD — privilege escalation przez niekompletną listę blokad VM

CVE-2026-34179CRITICAL9.1PL ✓same product

Canonical LXD: privilege escalation do admina klastra przez brak walidacji pola Type

CVE-2026-9640HIGH7.2PL ✓same product

LXD: privilege escalation przez przywracanie snapshotów z pominięciem polityk

CVE-2026-12411HIGH8.4PL ✓same product

Canonical LXD: nieuprawniony dostęp do woluminów innych gości przez /dev/lxd

CVE-2025-54289HIGH7.4same product

Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read p...