Allocation of Resources Without Limits or Throttling in LXD - CVE-2026-63299

 

Allocation of Resources Without Limits or Throttling in LXD - CVE-2026-63299

Published: August 1, 2026


Vulnerability identifier: #VU140681
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-63299
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in storagePoolVolumeTypePostMove and volume snapshot restore handling when moving storage volumes across projects or restoring snapshots. A remote user can move a large volume into a quota-limited project or restore a snapshot that exceeds current project limits to cause a denial of service.

This affects multi-tenant environments that rely on project disk quotas.


Affected software

LXD

How to mitigate CVE-2026-63299

Install security update from vendor's website.

LXD - addressed in versions 5.0.8, 5.21.6, 6.10

External References

Related Security Bulletins