Link following in LXD - CVE-2026-63294
Published: August 1, 2026
LXD
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code as root on the host.
The vulnerability exists due to improper link resolution in backup file handling in the image metadata unpacking and instance backup.yaml write logic when importing a crafted image and creating an instance from it. A remote user can supply an image containing a symlinked backup.yaml to overwrite a host file and execute arbitrary code as root on the host.
Exploitation requires image and instance creation rights in a project-confined environment, or an administrator to import or create an instance from an untrusted image.