Link following in LXD - CVE-2026-48749
Published: June 29, 2026
Vulnerability details
The vulnerability allows a remote user to read and write arbitrary files on the host.
The vulnerability exists due to improper link resolution in image extraction and the stopped-container file API when processing a specially crafted image containing a duplicate top-level rootfs symlink. A remote user can import a crafted image and access container files to read and write arbitrary files on the host.
This issue can expose host files with root privileges and may lead to arbitrary command execution.
Affected software
Debian Linux
lxd (Debian package)
How to mitigate CVE-2026-48749
lxd (Debian package) - update to 5.0.2+git20231211.1364ae4-9+deb13u7