Impact
An authenticated attacker can exploit a timing flaw in LXD’s configuration merging process. When an instance is copied to a target project, LXD performs restriction checks before the merge completes, creating a TOCTOU condition that permits the attacker to inject disallowed high‑privilege configuration into the copy before final validation. This flaw enables the placement of instances with elevated privileges into projects that are meant to restrict such configurations, thereby compromising the confidentiality, integrity, and potential availability of resources within those projects.
Affected Systems
Canonical LXD deployments are affected. Vulnerable versions are those earlier than 5.0.8 and earlier than 5.12.6, as noted by the vendor. Any installation that allows authenticated users to perform cross‑project instance copies is susceptible, regardless of network exposure.
Risk and Exploitability
The CVSS score of 9.9 marks this vulnerability as critical and indicates a high likelihood of successful exploitation. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires authenticated access but does not need elevated privileges beyond those granted to the copying user. Because the flaw arises from a TOCTOU race condition, it is likely easy to trigger once the copying operation is permitted, making the risk significant for systems that enable cross‑project instance copying.
OpenCVE Enrichment