CRITICAL
Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipulation in LXD
Published Sep 28, 2026
9.9
CRITICALCVSS 3.1
EPSS 0.52%
Description
Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root via a crafted subvolumes[].path entry in backup/optimized_header.yaml during a btrfs optimized backup import.
Affected products
-
Affected
- ≥ 4.0.0, < 4.0.14
- ≥ 5.0.0, < 5.0.10
- ≥ 5.21.0, < 5.21.8
- ≥ 6.0, < 6.10
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to LXD versions 4.0.14, 5.0.10, 5.21.8, 6.10 or later.
Weaknesses (1)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88257 Advisory
- https://github.com/canonical/lxd-private/pull/103 patch
- https://github.com/canonical/lxd-private/pull/104 patch
- https://github.com/canonical/lxd-private/pull/105 patch
- https://github.com/canonical/lxd-private/pull/84 patch
- https://github.com/canonical/lxd-private/pull/87 patch
- https://github.com/canonical/lxd/security/advisories/GHSA-h85r-gjgx-g2rv vendor-advisoryissue-tracking
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner canonical
Published Sep 28, 2026
Updated Sep 29, 2026
Reserved Sep 4, 2026
Link CVE-2026-85526
CISA Vulnrichment
Updated Sep 28, 2026
Red Hat
No data
GitHub
No data