LXC Vulnerability in Image-Build Scripts Affecting Arch Linux
CVE-2026-52727
What is CVE-2026-52727?
The lxc-ci product features continuous integration and image-build scripts for creating LXC containers. A significant issue arises from aspects of the Arch Linux image build process, where images created from the images/archlinux.yaml retain a pacman local-signing private key in an insecure manner. This private key, located at /etc/pacman.d/gnupg, is propagated across all containers or virtual machines derived from such images. An attacker who manages to control a package mirror or intercepts traffic from the mirror can exploit this vulnerability. They could use the shared signing key to sign malicious packages that would be erroneously trusted by clients, allowing for arbitrary code execution with root privileges upon installation. Arch Linux has addressed this concern in images released on or after May 28, 2026.
Affected Version(s)
lxc-ci < 2026-05-28
