Input validation error in LXD - CVE-2026-48752

 

Input validation error in LXD - CVE-2026-48752

Published: June 29, 2026


Vulnerability identifier: #VU135801
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-48752
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to read and write arbitrary files on the host.

The vulnerability exists due to improper input validation in the image tar extraction logic when processing a specially crafted container image containing a top-level templates symlink. A remote user can import a specially crafted image to read and write arbitrary files on the host.

This issue may also lead to arbitrary command execution on the host.


Affected software

LXD
Debian Linux
lxd (Debian package)

How to mitigate CVE-2026-48752

Install security update from vendor's website.

LXD - addressed in versions 4.0.11, 5.0.7, 5.21.5, 6.9
lxd (Debian package) - update to 5.0.2+git20231211.1364ae4-9+deb13u7

External References

Related Security Bulletins