Impact
The vulnerability is a path‑traversal flaw in the Btrfs storage driver’s unpackVolume routine. An attacker who can create instances can craft a backup/optimized_header.yaml with malicious subvolumes[].path entries. During import, the invalidated path is used to delete or overwrite arbitrary files or directories on the host filesystem with root privileges. This results in full control over host data, persistence, or denial of service.
Affected Systems
All Canonical LXD releases that include the vulnerable Btrfs driver and that are older than the patched versions listed as 4.0.14, 5.0.10, 5.21.8, or 6.10. The vulnerability affects the Linux host where LXD runs; any container image using the Btrfs storage backend is at risk.
Risk and Exploitability
The CVSS score of 9.9 classifies the issue as critical, while no EPSS data is available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with instance‑creation rights to perform a backup import. Once the malicious backup is processed, the attacker can manipulate arbitrary host files, effectively escalating privileges or disrupting the host. Given the requirement of local service access, the exposure is limited to environments where such users are present.
OpenCVE Enrichment