Sceawere
Vulnerability Detail
CVE-2026-87799UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
LXD Arbitrary File Write Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.9
- Creation Date
- 3h ago
- Vendor
- Canonical
- Product
- LXD
- Attack Type
- CWE-59 Improper link resolution before file access ('link following')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes in a project, or a malicious migration source server, to write attacker-controlled files to arbitrary paths on the target host as root, leading to full host compromise. The attacker does this with a crafted rsync or btrfs send stream that plants a symlink in the transferred volume, such as rootfs or root.img, and then writes through it.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.9",
"pubDate": "2026-09-28T14:17:21.427Z",
"pubdate": "2026-09-28T14:17:21.427Z",
"executiveSummary": "This vulnerability is an improper link resolution flaw within the Canonical LXD migration receive path. It affects versions 4.0 and later, presenting a critical security risk that can lead to complete host system compromise.\nThe vulnerability allows an authenticated attacker, either through the creation of instances, custom storage volumes, or by acting as a malicious migration source server, to perform arbitrary file writes on the host file system with root privileges.\nBy manipulating the migration process, an attacker can plant malicious symbolic links within transferred data structures, such as rootfs or root.img. When the LXD daemon processes these streams, it fails to safely validate or resolve the paths, resulting in the overwrite or creation of sensitive system files.\nThe exploitation of this flaw grants an attacker the ability to escalate privileges to root on the target host, effectively bypassing standard container isolation. This represents a significant breach of the security boundary between the container environment and the underlying host operating system. Organizations utilizing LXD must prioritize patching to the recommended versions to eliminate this attack vector and prevent unauthorized host-level access.",
"technicalDetails": "The root cause of this vulnerability lies in the insufficient sanitization and validation of symlinks during the unpacking or processing of data streams in the LXD migration receive path. Specifically, when LXD receives a migration stream—transmitted via rsync or btrfs send protocols—it attempts to write the transferred data to the local storage backend.\nThe vulnerability occurs because the migration receive process does not strictly enforce path constraints when encountering symbolic links present within the incoming volume data. An attacker can craft a malicious rsync or btrfs send stream that includes a symlink pointing to an arbitrary location on the host file system, such as /etc/shadow, /root/.ssh/authorized_keys, or other critical system binaries.\nThe exploitation flow proceeds as follows: First, the attacker initiates a migration or creates a volume using a crafted payload. During the transfer, the attacker injects a symlink into the rootfs or root.img file structure. When the target LXD daemon receives this stream, it blindly follows the symlink during the file writing phase. Because the migration process operates with elevated root privileges on the host to manage instance storage, the daemon writes the subsequent data from the stream to the path referenced by the malicious symlink.\nBy controlling the content of the data stream, the attacker gains the ability to overwrite or create files at any location on the host filesystem that the LXD service account can access. This effectively facilitates arbitrary file write primitives with root-level privileges.\nThe scope of impact is severe, as the attacker can write to configuration files, insert persistent backdoors, or overwrite system binaries to achieve full remote code execution and host compromise. This flaw exists in Canonical LXD versions 4.0 and later. Mitigation requires updating to the patched versions: 4.0.14, 5.0.10, 5.21.8, or 6.10, which incorporate logic to prevent improper link resolution and ensure that file system operations are confined to the intended storage paths."
}