Impact
The vulnerability is a path traversal flaw in the LXD CLI client that handles image export and copy operations. By supplying a malicious Content-Disposition header with a crafted filename, an attacker can cause the client to write files outside the intended directory. If the overridden file is executable or a critical system file, this can lead to arbitrary code execution or system compromise. The flaw originates from improper validation of the header value during the unified image export and copy features.
Affected Systems
Canonical LXD consumers using versions 4.0.2 through 4.0.13, 5.0.0 through 5.0.9, 5.21.0 through 5.21.7, and 6.0.0 through 6.9.9 on all supported platforms are affected.
Risk and Exploitability
The CVSS score of 4.2 indicates a moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation. However, the attack vector is inferred to be remote or MITM image servers communicating with a client that performs an export or copy. Successful exploitation requires the attacker to supply a crafted image file and direct the LXD client to download it, making it a targeted rather than mass exploitation scenario.
OpenCVE Enrichment