Impact
The vulnerability is caused by improper neutralization of special elements in LXD's handling of NVIDIA instance configuration. By inserting newline characters into the 'nvidia.driver.capabilities' or 'nvidia.require.*' values, an attacker can inject arbitrary configuration directives into the generated lxc.conf file. This allows the attacker to run arbitrary code on the host with the privileges of the LXD daemon, leading to potential full system compromise.
Affected Systems
Canonical LXD releases before 4.0.12, 5.0.8, or 5.12.6 are affected.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability. EPSS is not available, but the lack of a KEV listing suggests no known public exploits yet. The flaw requires an authenticated attacker with access to the LXD API; the attacker can manipulate the NVIDIA configuration stored by the LXD daemon, inject new directives, and execute code with daemon privileges.
OpenCVE Enrichment