Improper Neutralization of Special Elements in Output Used by a Downstream Component in LXD - CVE-2026-63298

 

Improper Neutralization of Special Elements in Output Used by a Downstream Component in LXD - CVE-2026-63298

Published: August 1, 2026


Vulnerability identifier: #VU140680
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-63298
CWE-ID: CWE-74
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Affected software:
LXD

Detailed vulnerability description

The vulnerability allows a remote user to execute arbitrary code on the host.

The vulnerability exists due to improper neutralization of special elements in output in the nvidia.driver.capabilities instance configuration handling when writing user-supplied configuration values to lxc.conf. A remote user can inject a newline character into the configuration value to inject arbitrary LXC configuration directives and execute arbitrary code on the host.

Exploitation requires permission to set instance configuration, and injected directives are processed when the container starts.


How to mitigate CVE-2026-63298

Install security update from vendor's website.

Sources