Impact
Canonical LXD’s btrfs storage driver, for releases 4.0.2 and later, allows a path‑traversal flaw to be exploited by an authenticated user with permission to create instances in a project. By embedding directory traversal sequences into a subvolume path that is transmitted either as part of an optimized backup’s header or a migration source header, the attacker can delete arbitrary files on the host and, if the host’s root filesystem is btrfs, write attacker‑controlled data to any host path. This results in full host compromise and effectively grants root‑level execution capabilities. The weakness maps to CWE‑22, path traversal.
Affected Systems
Affected systems are Canonical LXD installations using the btrfs storage driver. All versions from 4.0.2 up to (but not including) 4.0.14, from 5.0.2 up to 5.0.9, from 5.21.2 up to 5.21.7, and prior to 6.10 are vulnerable; the problem was fixed in LXD 4.0.14, 5.0.10, 5.21.8, and 6.10 and newer. The flaw impacts any host where the attacker can interact with LXD’s API as an authenticated client that may launch or manage instances within a project.
Risk and Exploitability
Risk and exploitability are high. The CVSS score of 9.6 indicates critical severity, and the EPSS score is not available but the lack of an EPSS value does not reduce the risk; the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. Exploitation requires the attacker to possess credentials that allow instance creation and to send a specially crafted backup or migration header containing traversal sequences. Once the header is processed, the host’s root filesystem files can be manipulated or deleted, allowing an attacker to insert malicious content, bypass authentication, or erase system files, leading to a complete host takeover.
OpenCVE Enrichment