Critical vulnerabilities in LXD allow container escape via backup import
Multiple critical vulnerabilities have been discovered in LXD container management software. CVE-2026-87799 and related flaws allow attackers to write files as root on the host system during backup import operations. These vulnerabilities affect LXD versions 4.0 and later, with severity ratings up to 9.9 on the CVSS scale. The issues involve improper handling of symbolic links during btrfs filesystem restore processes. Project maintainers have released fixed versions and recommend immediate patching and restricting backup imports from untrusted sources.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in