Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to LXD versions 4.0.14, 5.0.10, 5.21.8, 6.10 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 28 Sep 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canonical
Canonical lxd |
|
| Vendors & Products |
Canonical
Canonical lxd |
Mon, 28 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 28 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root via a crafted subvolumes[].path entry in backup/optimized_header.yaml during a btrfs optimized backup import. | |
| Title | Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipulation in LXD | |
| Weaknesses | CWE-22 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2026-09-28T13:53:42.731Z
Reserved: 2026-09-04T08:34:29.842Z
Link: CVE-2026-85526
Updated: 2026-09-28T13:53:38.667Z
Status : Deferred
Published: 2026-09-28T14:17:20.423
Modified: 2026-09-28T15:12:32.657
Link: CVE-2026-85526
No data.
OpenCVE Enrichment
Updated: 2026-09-28T15:30:02Z