TL;DR
Canonical has patched three critical LXD vulnerabilities rated CVSS 9.6 to 9.9. Each one lets a low-privileged user or a rogue migration source write or delete files as root on the host. Fixed releases are 4.0.14, 5.0.10, 5.21.8 and 6.10.
- Product: Canonical LXD
- Vulnerabilities: 3 flaws (CVE-2026-87799, CVE-2026-85185, CVE-2026-85526)
- Highest severity: 9.9 (Critical · CVSSv3)
- Worst impact: Arbitrary file write on host via symlink in migration stream
- Status: No confirmed exploitation yet; patches available
- Action: Update to 4.0.14, 5.0.10, 5.21.8, 6.10 now
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-87799 | 9.9 | CWE-59 | 4.0.14, 5.0.10, 5.21.8 (+1) | Not exploited |
| CVE-2026-85526 | 9.9 | CWE-22 | 4.0.14, 5.0.10, 5.21.8 (+1) | Not exploited |
| CVE-2026-85185 | 9.6 | CWE-22 | 4.0.14, 5.0.10, 5.21.8 (+1) | Not exploited |
Route critical CVEs to one Slack channel, everything else to another.
Try Team free for 14 daysWhy These LXD Vulnerabilities Matter
LXD is Canonical’s manager for system containers and virtual machines. It runs everything from a single laptop instance to clustered data center racks. Many teams use it to build small private clouds where several projects share one host.
That shared model is exactly what these flaws break. A user who may only create instances or custom volumes in a restricted project can reach root on the host. In a multi-tenant setup, one tenant could compromise every other tenant on the machine.
How the Attacks Work
CVE-2026-87799: Symlinks in the Migration Stream (CVSS 9.9)
When LXD receives an instance or custom volume through migration, it hands the incoming data to rsync or to btrfs receive. Both tools replay the stream using normal path-based system calls. Neither tool refuses to follow symlinks along the way.
As a result, a malicious migration source can plant a symlink early in the stream. Later entries then get written through it to paths outside the volume, as root. For virtual machines, the same trick can redirect the root disk image. The advisory notes that optimized ZFS transfers are not affected. The same advisory text also references Incus, the community fork of LXD, which shares this code path.
CVE-2026-85185: Unvalidated btrfs Subvolume Path (CVSS 9.6)
The btrfs storage driver reads a subvolume path field from attacker-supplied backup and migration headers. LXD joins that path to the pool mount point without any containment check. A path that climbs out of the pool then reaches file removal and rename operations that run as root.
The advisory states that this is a “DISTINCT sink” from the earlier fixes for CVE-2026-66897 and CVE-2026-66898. On hosts whose root filesystem is btrfs, such as some Fedora, SUSE and Ubuntu installs, the attacker can place content anywhere on the host. That raises the ceiling to remote code execution.
CVE-2026-85526: Path Traversal in btrfs Backup Restore (CVSS 9.9)
This flaw hits the same field through a different route: restoring an optimized backup tarball onto a btrfs pool. Any authenticated user with permission to create instances can craft a tarball whose path escapes the volume. The advisory calls the result “effectively a host-level filesystem compromise” in multi-tenant projects.
Affected Versions and Exploitation Status
CVE-2026-87799 affects LXD 4.0 and later. The two btrfs flaws affect LXD 4.0.2 and later. The advisories do not report any exploitation in the wild, and public proof-of-concept has been confirmed.
Patch and Mitigation Steps
Upgrade to LXD 4.0.14, 5.0.10, 5.21.8, 6.10, or the 6.9 build at commit bf243da. You can review each fix in the official LXD security advisories on GitHub. If you cannot patch right away, apply these workarounds:
- Only let trusted users create instances and custom storage volumes.
- Only migrate instances from servers you trust.
- Do not import btrfs optimized backups from untrusted sources.
- In multi-tenant projects, consider blocking backup import for non-admin members until you patch.
Because all three LXD vulnerabilities turn project-level access into host-level control, shared LXD hosts should move to the top of the patch list.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!