Description
Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes in a project, or a malicious migration source server, to write attacker-controlled files to arbitrary paths on the target host as root, leading to full host compromise. The attacker does this with a crafted rsync or btrfs send stream that plants a symlink in the transferred volume, such as rootfs or root.img, and then writes through it.
Published: 2026-09-28
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: Remote code execution leading to full host compromise
Action: Immediate patch
AI Analysis

Impact

An authenticated client capable of creating instances or storage volumes, or a malicious migration source, can supply a crafted migration stream containing a symlink to a privileged path. During the receive phase, LXD does not correctly resolve the symlink, allowing the attacker to write arbitrary files as the host’s root user. This flaw directly enables complete compromise of the LXD host, exposing all data and services running on it.

Affected Systems

The vulnerability affects Canonical’s LXD product on Linux operating systems. All LXD versions starting with 4.0 up to but not including 4.0.14, 5.0.10, 5.21.8, and 6.10 are susceptible. Users of LXD who can instantiate containers or custom storage volumes within any project, or who accept migration streams from other servers, are exposed.

Risk and Exploitability

The CVSS score of 9.9 marks this as critical. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, implying that known exploitation activity has not been reported publicly. Nonetheless, any authenticated and privileged user has the exploitability conditions, and the attack vector is via the migration receive path, which is likely reachable over a network where migration traffic is allowed. Given the severity and the ability to execute arbitrary code as root, the risk of exploitation remains high.

Generated by OpenCVE AI on September 28, 2026 at 15:25 UTC.

Remediation

Vendor Solution

Upgrade to LXD versions 4.0.14, 5.0.10, 5.21.8, 6.10 or later.


OpenCVE Recommended Actions

  • Update LXD to version 4.0.14, 5.0.10, 5.21.8, or 6.10 or newer, as these releases include the fix for symlink resolution in the migration receive path.
  • Restrict migration receive access to trusted, privileged hosts or reconfigure the firewall to block untrusted migration traffic, thereby preventing attacks from malicious migration sources.
  • Review project permissions to ensure only authorized users can create instances or storage volumes; consider tightening the permission model to limit the scope of containers that can be migrated.

Generated by OpenCVE AI on September 28, 2026 at 15:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Canonical
Canonical lxd
Vendors & Products Canonical
Canonical lxd

Mon, 28 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes in a project, or a malicious migration source server, to write attacker-controlled files to arbitrary paths on the target host as root, leading to full host compromise. The attacker does this with a crafted rsync or btrfs send stream that plants a symlink in the transferred volume, such as rootfs or root.img, and then writes through it.
Title Arbitrary file write on LXD host via symlink in migration stream
Weaknesses CWE-59
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: canonical

Published:

Updated: 2026-09-28T16:32:28.274Z

Reserved: 2026-09-09T10:00:46.383Z

Link: CVE-2026-87799

cve-icon Vulnrichment

Updated: 2026-09-28T16:22:29.745Z

cve-icon NVD

Status : Deferred

Published: 2026-09-28T14:17:21.427

Modified: 2026-09-28T17:17:51.787

Link: CVE-2026-87799

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T15:30:02Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')