CVE-2026-85526

Summary

Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root via a crafted subvolumes[].path entry in backup/optimized_header.yaml during a btrfs optimized backup import.

Affected Software

VendorProductVersion RangeStatus
CanonicalLXD4.0.0 < 4.0.14affected
CanonicalLXD5.0.0 < 5.0.10affected
CanonicalLXD5.21.0 < 5.21.8affected
CanonicalLXD6.0 < 6.10affected

Weaknesses

  • CWE-22: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: total

References