Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when security.devlxd.management.volumes is enabled.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Upgrade to LXD version 6.9 or later.
Workaround
No workaround given by the vendor.
References
History
Fri, 26 Jun 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when security.devlxd.management.volumes is enabled. | |
| Title | Broken Access Control in Canonical LXD DevLXD API | |
| Weaknesses | CWE-639 CWE-862 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2026-06-26T16:02:55.284Z
Reserved: 2026-06-16T15:07:27.771Z
Link: CVE-2026-12411
No data.
No data.
No data.
OpenCVE Enrichment
No data.