Link following in LXD - CVE-2026-48750
Published: June 29, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code on the host.
The vulnerability exists due to improper link resolution in the /instances/$name/exec endpoint exec-output handling when processing the record-output parameter for a crafted image. A remote user can create an instance from a crafted image and invoke exec with record-output enabled to execute arbitrary code on the host.
The issue arises because a top-level exec-output symlink from the image can be extracted as is, causing stdout and stderr files to be written to an arbitrary host location.
Affected software
Debian Linux
lxd (Debian package)
How to mitigate CVE-2026-48750
lxd (Debian package) - update to 5.0.2+git20231211.1364ae4-9+deb13u7