Canonical / LXD
35 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-34177 | VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf | CRITICAL | 9.1 | Apr 9, 2026 |
| CVE-2026-28384 | Authenticated RCE via unsanitized compression_algorithm | CRITICAL | 9.4 | Mar 12, 2026 |
| CVE-2026-3351 | Authorization Bypass in LXD GET /1.0/certificates Endpoint | MEDIUM | 5.3 | Mar 3, 2026 |
| CVE-2025-54293 | Path Traversal in LXD Instance Log File Retrieval | HIGH | 7.1 | Oct 2, 2025 |
| CVE-2025-54292 | Client-Side Path Traversal in LXD-UI | MEDIUM | 4.8 | Oct 2, 2025 |
| CVE-2025-54291 | Project existence disclosure in LXD images API | MEDIUM | 6.9 | Oct 2, 2025 |
| CVE-2025-54290 | Project Existence Disclosure via Error Handling in LXD Image Export | MEDIUM | 6.9 | Oct 2, 2025 |
| CVE-2025-54289 | Privilege Escalation via WebSocket Connection Hijacking in LXD Operations API | HIGH | 7.4 | Oct 2, 2025 |
| CVE-2025-54288 | Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server | MEDIUM | 5.1 | Oct 2, 2025 |
| CVE-2025-54287 | Arbitrary File Read via Template Injection in Snapshot Patterns | HIGH | 7.1 | Oct 2, 2025 |
| CVE-2025-54286 | CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI | HIGH | 7.5 | Oct 2, 2025 |
| CVE-2024-6219 | Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honour… | LOW | 3.8 | Dec 5, 2024 |
| CVE-2024-6156 | Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store. | LOW | 3.8 | Dec 5, 2024 |
| CVE-2023-49721 | An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot. | MEDIUM | 6.7 | Feb 14, 2024 |
| CVE-2023-48733 | An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot. | MEDIUM | 6.7 | Feb 14, 2024 |
| CVE-2016-1582 | LXD before 2.0.2 does not properly set permissions when switching an unprivileged container into privileged mode, which allows local users to access arbitrary… | MEDIUM | 5.5 | Jun 9, 2016 |
| CVE-2016-1581 | LXD before 2.0.2 uses world-readable permissions for /var/lib/lxd/zfs.img when setting up a loop based ZFS pool, which allows local users to copy and read data… | MEDIUM | 5.5 | Jun 9, 2016 |
Showing 26 to 35 of 35 CVEs