Input validation error in LXD - CVE-2026-48752
Published: June 29, 2026
Vulnerability details
The vulnerability allows a remote user to read and write arbitrary files on the host.
The vulnerability exists due to improper input validation in the image tar extraction logic when processing a specially crafted container image containing a top-level templates symlink. A remote user can import a specially crafted image to read and write arbitrary files on the host.
This issue may also lead to arbitrary command execution on the host.
Affected software
Debian Linux
lxd (Debian package)
How to mitigate CVE-2026-48752
lxd (Debian package) - update to 5.0.2+git20231211.1364ae4-9+deb13u7