Improper Link Resolution in Canonical LXD Versions
CVE-2026-87799

9.9CRITICAL

Key Information:

Vendor

Canonical

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-87799?

An improper link resolution vulnerability exists in the migration receive path in Canonical LXD versions 4.0 and later. Specifically, it allows an authenticated user with permissions to create instances or custom storage volumes, or a rogue migration source server, to exploit this flaw. By manipulating an rsync or btrfs send stream, the attacker can introduce a symlink within the transferred volume that enables writing to arbitrary paths on the target host as a root user. If successful, this leads to a potential full host compromise, posing significant risks to the integrity and confidentiality of the affected system.

Affected Version(s)

LXD Linux 4.0.0 < 4.0.14

LXD Linux 5.0.0 < 5.0.10

LXD Linux 5.21.0 < 5.21.8

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.