Path Traversal Vulnerability in Canonical LXD Affecting Btrfs Storage Driver
CVE-2026-85185

9.6CRITICAL

Key Information:

Vendor

Canonical

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-85185?

A path traversal vulnerability exists in the btrfs storage driver of Canonical LXD that allows authenticated clients with the right permissions to manipulate subvolume paths using crafted input. This enables attackers to delete arbitrary files on the host system or place malicious content at specified host locations. The issue arises when an attacker sends a specially designed subvolume path containing '../' sequences, either via the optimized_header.yaml during a btrfs backup or through a migration header from a compromised source, putting the host at risk of significant compromise.

Affected Version(s)

LXD Linux 4.0.2 < 4.0.14

LXD Linux 5.0.0 < 5.0.10

LXD Linux 5.21.0 < 5.21.8

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.