Impact
The vulnerability arises from improper link resolution in the recursive file pull feature of the LXD CLI client. An attacker who has obtained root access inside a virtual machine can supply a modified lxd-agent that presents inconsistent directory listings and stat results. When the client performs a pull operation, it resolves file paths without proper sanitization, allowing the attacker to write executable code or modify system files anywhere on the host machine. As a result, an attacker can escape the isolation provided by the virtual environment and compromise the host system, potentially leading to full system takeover.
Affected Systems
Canonical LXD releases from 4.0.2 through 6.9 are affected. The vulnerability is fixed in LXD 4.0.14, 5.0.10, and 5.21.8 and later. The affected environment is a Linux host running the LXD client interacting with virtual machines.
Risk and Exploitability
The CVSS score of 5.8 classifies this issue as moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector requires an attacker to already have root privileges inside a VM and to supply a tampered lxd-agent; therefore, it is an exploited privilege escalation path rather than a publicly reachable network attack. The lack of remote exploitation guards and the need for internal VM compromise somewhat reduce immediate risk but do not eliminate it.
OpenCVE Enrichment