Impact
During the import or unpacking of a crafted image or backup archive, LXD fails to validate the backup.yaml file when it is a symbolic link. The flaw, identified as CWE‑59, allows an attacker to supply a malicious archive that contains a symlinked backup.yaml, causing LXD to process unconfined configuration metadata and execute arbitrary commands with root privileges on the host. The result is a full root privilege escalation without any additional authentication or elevated permissions.
Affected Systems
Canonical LXD is affected. Any release prior to LXD 4.0.12, LXD 5.0.8, LXD 5.12.6, or LXD 6.10 is vulnerable. Updating to the respective cited versions or later protects against this attack.
Risk and Exploitability
The CVSS score of 9.9 indicates critical severity. EPSS data is unavailable, so the probability of exploitation cannot be quantified, but the flaw permits immediate elevation to root via an import operation that may be available to unprivileged users or through the LXD API. It is not listed in the CISA KEV catalog, yet its impact and ease of exploitation make it a high‑risk vulnerability. An attacker can locally or remotely inject a malicious archive, trigger the import, and gain unrestricted control of the underlying host system.
OpenCVE Enrichment