CVE-2026-87798: falha de média gravidade em Canonical LXD
LXD client recursive file pull allows directory escape via malicious VM agent
Publicada em
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 5.8epss 0.2%
probabilidade de exploração
0.2%top 92% das CVEs
exploração observada
nãonenhuma fonte reporta
Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.0.2 up to 6.9 (fixed in 4.0.14, 5.0.10 and 5.21.8) on Linux allows an attacker with root access inside a virtual machine to write attacker-controlled files or directory trees to arbitrary paths on the client host, with the operator's privileges. The attacker does this by using a modified lxd-agent that returns inconsistent SFTP directory listings and Lstat results.
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:N
Produtos afetados
Canonical · LXDCVEs relacionadas — Canonical LXD
No mesmo produto, das mais perigosas para as menos.
CVE-2026-63294CRITICALRoot RCE via image backup.yaml symlinkEPSS 0.9%CVE-2026-66897CRITICALInstance template path traversal allows arbitrary host file write as rootEPSS 0.7%CVE-2026-63298HIGHLXD arbitrary lxc.conf directive injection via NVIDIA instance configurationEPSS 0.7%CVE-2026-9640HIGHLXD Snapshot Import Privilege Escalation VulnerabilityEPSS 0.6%CVE-2026-66898CRITICALPath traversal via unvalidated instance name in backup tarball restore enables root file write / RCEEPSS 0.6%CVE-2026-63293CRITICALArbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as rootEPSS 0.6%