Relative Path Traversal in LXD - CVE-2026-85185

 

Relative Path Traversal in LXD - CVE-2026-85185

Published: September 25, 2026


Vulnerability identifier: #VU152253
CSH Severity: Medium
CVSS v4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-85185
CWE-ID: CWE-23
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to delete arbitrary host files and place attacker-controlled content outside the storage pool.

The vulnerability exists due to relative path traversal in the btrfs storage driver when processing attacker-supplied subvolume paths in optimized backup headers or migration metadata. A remote user can supply a subvolume path containing directory traversal sequences to delete arbitrary host files or place attacker-controlled content outside the storage pool.

Content placement outside the pool is limited to deployments where the btrfs storage pool is on the host root filesystem.


Affected software

LXD

How to mitigate CVE-2026-85185

Install security update from vendor's website.

LXD - addressed in versions 4.0.14, 5.0.10, 5.21.8, 6.10

External References

Related Security Bulletins