Description
Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete arbitrary files on the host as root. On hosts whose root filesystem is btrfs, the client can also place attacker-controlled content at arbitrary host paths, leading to full host compromise. The client does this with a crafted subvolume path containing ../ sequences, sent in either of two ways: in the optimized_header.yaml of an optimized btrfs backup, or in the btrfs migration header sent by a malicious migration source.
Published: 2026-09-28
Score: 9.6 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution (Root Privileges)
Action: Immediate Patch
AI Analysis

Impact

Canonical LXD’s btrfs storage driver, for releases 4.0.2 and later, allows a path‑traversal flaw to be exploited by an authenticated user with permission to create instances in a project. By embedding directory traversal sequences into a subvolume path that is transmitted either as part of an optimized backup’s header or a migration source header, the attacker can delete arbitrary files on the host and, if the host’s root filesystem is btrfs, write attacker‑controlled data to any host path. This results in full host compromise and effectively grants root‑level execution capabilities. The weakness maps to CWE‑22, path traversal.

Affected Systems

Affected systems are Canonical LXD installations using the btrfs storage driver. All versions from 4.0.2 up to (but not including) 4.0.14, from 5.0.2 up to 5.0.9, from 5.21.2 up to 5.21.7, and prior to 6.10 are vulnerable; the problem was fixed in LXD 4.0.14, 5.0.10, 5.21.8, and 6.10 and newer. The flaw impacts any host where the attacker can interact with LXD’s API as an authenticated client that may launch or manage instances within a project.

Risk and Exploitability

Risk and exploitability are high. The CVSS score of 9.6 indicates critical severity, and the EPSS score is not available but the lack of an EPSS value does not reduce the risk; the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. Exploitation requires the attacker to possess credentials that allow instance creation and to send a specially crafted backup or migration header containing traversal sequences. Once the header is processed, the host’s root filesystem files can be manipulated or deleted, allowing an attacker to insert malicious content, bypass authentication, or erase system files, leading to a complete host takeover.

Generated by OpenCVE AI on September 28, 2026 at 15:28 UTC.

Remediation

Vendor Solution

Upgrade to LXD versions 4.0.14, 5.0.10, 5.21.8, 6.10 or later.


OpenCVE Recommended Actions

  • Upgrade Canonical LXD to version 4.0.14 or later, 5.0.10 or later, 5.21.8 or later, or 6.10 or later.
  • If an upgrade cannot be performed immediately, remove or restrict the ‘create instance’ permission for untrusted clients or projects in LXD, ensuring that only trusted users can launch containers.
  • Disable or block the use of optimized btrfs backup and migration features on vulnerable hosts to prevent the injection of malicious headers.

Generated by OpenCVE AI on September 28, 2026 at 15:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Canonical
Canonical lxd
Vendors & Products Canonical
Canonical lxd

Mon, 28 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete arbitrary files on the host as root. On hosts whose root filesystem is btrfs, the client can also place attacker-controlled content at arbitrary host paths, leading to full host compromise. The client does this with a crafted subvolume path containing ../ sequences, sent in either of two ways: in the optimized_header.yaml of an optimized btrfs backup, or in the btrfs migration header sent by a malicious migration source.
Title Path traversal in LXD btrfs storage driver allows arbitrary file deletion and write on host as root
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: canonical

Published:

Updated: 2026-09-28T16:32:28.529Z

Reserved: 2026-09-03T11:46:34.569Z

Link: CVE-2026-85185

cve-icon Vulnrichment

Updated: 2026-09-28T16:22:32.628Z

cve-icon NVD

Status : Deferred

Published: 2026-09-28T14:17:20.130

Modified: 2026-09-28T17:17:51.013

Link: CVE-2026-85185

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T15:30:02Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')