Link following in LXD - CVE-2026-87799
Published: September 25, 2026
Vulnerability details
The vulnerability allows a remote user to write attacker-controlled files to arbitrary paths on the target host.
The vulnerability exists due to improper handling of symbolic links in the migration stream receiver when receiving an instance or custom storage volume through migration. A remote user can supply a crafted migration stream containing a symbolic link that causes later entries to be written through it to write attacker-controlled files to arbitrary paths on the target host.
For virtual machines, a crafted stream can replace the root.img block file with a symbolic link before the block stream is written through it.