Input validation error in LXD - CVE-2026-48755

 

Input validation error in LXD - CVE-2026-48755

Published: June 29, 2026


Vulnerability identifier: #VU135803
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-48755
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper input validation in backup compression algorithm handling when processing backup requests with a user-supplied compression_algorithm value. A remote user can supply a crafted compression algorithm with injected arguments to execute arbitrary code.

The issue can be exploited to achieve an arbitrary file write on the host, which may be leveraged for command execution.


Affected software

LXD
Debian Linux
lxd (Debian package)

How to mitigate CVE-2026-48755

Install security update from vendor's website.

LXD - addressed in versions 4.0.11, 5.0.7, 5.21.5, 6.9
lxd (Debian package) - update to 5.0.2+git20231211.1364ae4-9+deb13u7

External References

Related Security Bulletins