Improper Authorization in LXC - CVE-2026-39402
Published: April 30, 2026
LXC
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper access control in lxc-user-nic delete authorization logic when deleting OVS-attached network interfaces. A local user can request deletion of another user's OVS port to cause a denial of service.
This is limited to multi-tenant environments using lxc-user-nic with OpenVswitch bridges, and exploitation requires a valid lxc-usernet policy entry on the same bridge.