Sceawere
Vulnerability Detail
CVE-2026-85526UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
LXD Btrfs Path Traversal Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.9
- Creation Date
- 3h ago
- Vendor
- Canonical
- Product
- LXD
- Attack Type
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root via a crafted subvolumes[].path entry in backup/optimized_header.yaml during a btrfs optimized backup import.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.9",
"pubDate": "2026-09-28T14:17:20.423Z",
"pubdate": "2026-09-28T14:17:20.423Z",
"executiveSummary": "A path traversal vulnerability exists in the Btrfs storage driver component of Canonical LXD. This flaw arises from insufficient validation of input provided within the 'subvolumes[].path' field of the 'backup/optimized_header.yaml' file during a Btrfs optimized backup import process. An attacker possessing instance creation privileges can leverage this vulnerability to perform arbitrary file deletion or replacement on the underlying host filesystem with root-level permissions. The vulnerability poses a critical security risk to the host environment, as it effectively allows an authenticated user, typically constrained within an LXD container, to escape those boundaries and manipulate host-side configuration or binary files. Successful exploitation requires an attacker to have the ability to initiate an instance import operation using a maliciously crafted backup archive. Given the potential for complete system compromise and privilege escalation, immediate patching or implementation of strict access controls regarding the import of untrusted backup archives is required.",
"technicalDetails": "The vulnerability resides within the 'unpackVolume' function of the Btrfs storage driver in LXD. When performing an optimized backup import, LXD parses the 'backup/optimized_header.yaml' file to reconstruct subvolumes associated with the instance. The 'subvolumes[].path' entry is used to define the destination path for these subvolumes on the host system. The flaw stems from a lack of rigorous sanitization and canonicalization checks on this path variable.\nSpecifically, the 'unpackVolume' function fails to prevent the use of directory traversal sequences (such as '../') within the 'subvolumes[].path' parameter. Because the import process runs with root privileges to manage storage subvolumes and mount points, an attacker can manipulate these paths to resolve to sensitive locations outside the intended storage directory on the host filesystem.\nThe attack flow proceeds as follows: First, an attacker with sufficient privileges to create instances and import backups constructs a malicious archive. Inside this archive, the 'backup/optimized_header.yaml' file is modified to contain a 'subvolumes[].path' value that points to a sensitive file or directory on the host, such as '/etc/shadow', '/root/.ssh/authorized_keys', or system binaries. When the user initiates the import process, the LXD daemon processes the malicious YAML header.\nDuring the 'unpackVolume' operation, the Btrfs driver uses the attacker-controlled path to perform filesystem operations. If the path targets a directory that exists, the driver may perform recursive deletions or replacements of files within that directory. If the path points to an existing file, the driver may overwrite, truncate, or otherwise replace the file contents with those provided in the backup archive. Because these operations are executed by the LXD daemon under the context of the root user, the filesystem protection mechanisms are bypassed.\nThis vulnerability effectively allows a container-level user to perform arbitrary write and delete operations on the host's root filesystem. The post-exploitation impact is severe, enabling attackers to replace system binaries, modify configuration files to establish persistence, or inject credentials to gain full control over the host operating system. The vulnerability is restricted to environments utilizing the Btrfs storage driver for LXD backups."
}