Path Traversal Vulnerability in Canonical LXD Btrfs Driver
CVE-2026-85526

9.9CRITICAL

Key Information:

Vendor

Canonical

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-85526?

A vulnerability exists in the Btrfs storage driver used by Canonical LXD on Linux systems, which allows an authenticated user with the ability to create instances to exploit crafted entries in backup configurations. This vulnerability enables such users to delete or replace arbitrary files and directories on the host filesystem with root privileges. A crafted subvolumes[].path entry in the backup/optimized_header.yaml can lead to unauthorized modifications to the filesystem, posing significant risks to system integrity and security.

Affected Version(s)

LXD Linux 4.0.0 < 4.0.14

LXD Linux 5.0.0 < 5.0.10

LXD Linux 5.21.0 < 5.21.8

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.