Allocation of Resources Without Limits or Throttling in LXD - CVE-2026-63299
Published: August 1, 2026
LXD
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in storagePoolVolumeTypePostMove and volume snapshot restore handling when moving storage volumes across projects or restoring snapshots. A remote user can move a large volume into a quota-limited project or restore a snapshot that exceeds current project limits to cause a denial of service.
This affects multi-tenant environments that rely on project disk quotas.