Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6212-1 | incus security update |
Debian DSA |
DSA-6213-1 | lxd security update |
Github GHSA |
GHSA-q96j-3fmm-7fv4 | LXD: Importing a crafted backup leads to project restriction bypass |
Wed, 22 Apr 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:* |
Fri, 10 Apr 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canonical
Canonical lxd |
|
| Vendors & Products |
Canonical
Canonical lxd |
Thu, 09 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 09 Apr 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Canonical LXD before 6.8, the backup import path validates project restrictions against backup/index.yaml in the supplied tar archive but creates the instance from backup/container/backup.yaml, a separate file in the same archive that is never checked against project restrictions. An authenticated remote attacker with instance-creation permission in a restricted project can craft a backup archive where backup.yaml carries restricted settings such as security.privileged=true or raw.lxc directives, bypassing all project restriction enforcement and allowing full host compromise. | |
| Title | Importing a crafted backup leads to project restriction bypass | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2026-04-09T11:55:20.431Z
Reserved: 2026-03-26T09:24:08.449Z
Link: CVE-2026-34178
Updated: 2026-04-09T11:54:48.483Z
Status : Analyzed
Published: 2026-04-09T10:16:21.820
Modified: 2026-04-22T20:55:16.703
Link: CVE-2026-34178
No data.
OpenCVE Enrichment
Updated: 2026-04-10T09:33:02Z
Debian DSA
Github GHSA