Impact
An authenticated client capable of creating instances or storage volumes, or a malicious migration source, can supply a crafted migration stream containing a symlink to a privileged path. During the receive phase, LXD does not correctly resolve the symlink, allowing the attacker to write arbitrary files as the host’s root user. This flaw directly enables complete compromise of the LXD host, exposing all data and services running on it.
Affected Systems
The vulnerability affects Canonical’s LXD product on Linux operating systems. All LXD versions starting with 4.0 up to but not including 4.0.14, 5.0.10, 5.21.8, and 6.10 are susceptible. Users of LXD who can instantiate containers or custom storage volumes within any project, or who accept migration streams from other servers, are exposed.
Risk and Exploitability
The CVSS score of 9.9 marks this as critical. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, implying that known exploitation activity has not been reported publicly. Nonetheless, any authenticated and privileged user has the exploitability conditions, and the attack vector is via the migration receive path, which is likely reachable over a network where migration traffic is allowed. Given the severity and the ability to execute arbitrary code as root, the risk of exploitation remains high.
OpenCVE Enrichment