Relative Path Traversal in LXD - CVE-2026-85185
Published: September 25, 2026
Vulnerability details
The vulnerability allows a remote user to delete arbitrary host files and place attacker-controlled content outside the storage pool.
The vulnerability exists due to relative path traversal in the btrfs storage driver when processing attacker-supplied subvolume paths in optimized backup headers or migration metadata. A remote user can supply a subvolume path containing directory traversal sequences to delete arbitrary host files or place attacker-controlled content outside the storage pool.
Content placement outside the pool is limited to deployments where the btrfs storage pool is on the host root filesystem.