Improper Link Resolution in Canonical LXD Versions
CVE-2026-87799
9.9CRITICAL
What is CVE-2026-87799?
An improper link resolution vulnerability exists in the migration receive path in Canonical LXD versions 4.0 and later. Specifically, it allows an authenticated user with permissions to create instances or custom storage volumes, or a rogue migration source server, to exploit this flaw. By manipulating an rsync or btrfs send stream, the attacker can introduce a symlink within the transferred volume that enables writing to arbitrary paths on the target host as a root user. If successful, this leads to a potential full host compromise, posing significant risks to the integrity and confidentiality of the affected system.
Affected Version(s)
LXD Linux 4.0.0 < 4.0.14
LXD Linux 5.0.0 < 5.0.10
LXD Linux 5.21.0 < 5.21.8
