LXC Vulnerability in Image-Build Scripts Affecting Arch Linux
CVE-2026-52727

7.2HIGH

Key Information:

Vendor

Lxc

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-52727?

The lxc-ci product features continuous integration and image-build scripts for creating LXC containers. A significant issue arises from aspects of the Arch Linux image build process, where images created from the images/archlinux.yaml retain a pacman local-signing private key in an insecure manner. This private key, located at /etc/pacman.d/gnupg, is propagated across all containers or virtual machines derived from such images. An attacker who manages to control a package mirror or intercepts traffic from the mirror can exploit this vulnerability. They could use the shared signing key to sign malicious packages that would be erroneously trusted by clients, allowing for arbitrary code execution with root privileges upon installation. Arch Linux has addressed this concern in images released on or after May 28, 2026.

Affected Version(s)

lxc-ci < 2026-05-28

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.