No advisories yet.
Solution
Upgrade to LXD versions 4.0.13, 5.0.9, 5.21.7, 6.10 or later.
Workaround
No workaround given by the vendor.
Mon, 24 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Aug 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canonical
Canonical lxd |
|
| Vendors & Products |
Canonical
Canonical lxd |
Mon, 24 Aug 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target template paths specified in metadata.yaml, LXD validates the path against a confined os.Root directory handle but subsequently opens and creates the file using os.Create with an unconfined string path. This discrepancy between path resolution checks and file creation allows an attacker to escape directory confinement, overwrite root-owned host files, and achieve host root code execution. | |
| Title | Instance template path traversal allows arbitrary host file write as root | |
| Weaknesses | CWE-22 CWE-23 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2026-08-24T13:01:26.966Z
Reserved: 2026-07-28T07:41:26.310Z
Link: CVE-2026-66897
Updated: 2026-08-24T13:00:13.173Z
Status : Received
Published: 2026-08-24T10:16:39.767
Modified: 2026-08-24T14:16:57.067
Link: CVE-2026-66897
No data.
OpenCVE Enrichment
Updated: 2026-08-24T11:00:09Z