Allocation of Resources Without Limits or Throttling in LXD - CVE-2026-63299

 

Allocation of Resources Without Limits or Throttling in LXD - CVE-2026-63299

Published: August 1, 2026


Vulnerability identifier: #VU140681
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-63299
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
LXD

Detailed vulnerability description

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in storagePoolVolumeTypePostMove and volume snapshot restore handling when moving storage volumes across projects or restoring snapshots. A remote user can move a large volume into a quota-limited project or restore a snapshot that exceeds current project limits to cause a denial of service.

This affects multi-tenant environments that rely on project disk quotas.


How to mitigate CVE-2026-63299

Install security update from vendor's website.

Sources