Impact
The vulnerability is an authorization bypass in LXD that allows an authenticated user to create or modify an instance within a project configured with restricted.containers.privilege=isolated without setting the security.idmap.isolated key. Because LXD does not enforce the isolation setting when the key is omitted, the attacker can run containers with elevated privileges that were intended to be blocked by project isolation. This flaw can lead to privilege escalation and environmental compromise within the project.
Affected Systems
The affected vendor is Canonical, with its LXD container hypervisor. Attackers can target LXD versions earlier than 4.0.12, 5.0.8, 5.12.6, or 6.10, which are the last releases before the fix was introduced. The project isolation configuration described in the advisory is a feature in these LXD versions.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact level, and no EPSS score is available, which suggests that automated exploitation activity has not been reported yet. The flaw is not listed in the CISA KEV catalog. The likely attack vector requires an authenticated session to LXD, meaning existing access to a user account that has permission to create or update instances. Once authenticated, the attacker can bypass the project isolation restrictions by simply omitting the security.idmap.isolated key.
OpenCVE Enrichment