CVE-2026-85526 PUBLISHED

Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipulation in LXD

Assigner: canonical
Reserved: 04.09.2026 Published: 28.09.2026 Updated: 29.09.2026

Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root via a crafted subvolumes[].path entry in backup/optimized_header.yaml during a btrfs optimized backup import.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.9

Product Status

Vendor Canonical
Product LXD
Versions Default: unaffected
  • affected from 4.0.0 to 4.0.14 (excl.)
  • affected from 5.0.0 to 5.0.10 (excl.)
  • affected from 5.21.0 to 5.21.8 (excl.)
  • affected from 6.0 to 6.10 (excl.)

Solutions

Upgrade to LXD versions 4.0.14, 5.0.10, 5.21.8, 6.10 or later.

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE

Impacts

  • CAPEC-126 Path Traversal