Critical LXD Security Flaws Expose Multi-Tenant Hosts to Compromise; Urgent Patch Required

October 1, 2026
Critical LXD Security Flaws Expose Multi-Tenant Hosts to Compromise; Urgent Patch Required
  • The report centers on CVE-2026-87799 and related LXD backup/import security flaws, showing how migration and restore processes can be exploited to achieve host-level compromise in multi-tenant environments.

  • Two exploitation paths are described: on migration, streams handed to rsync or btrfs receive can allow symlink traversal; on restore, an attacker-supplied backup header can steer subvolume paths to escape the destination volume.

  • Hardening guidance includes upgrading to fixed releases, restricting import paths to trusted identities, only accepting migrations from controlled servers, avoiding btrfs-optimized backups from untrusted sources, and limiting backup import for non-admins in multi-tenant setups until upgrades are complete.

  • Affected versions are specified: CVE-2026-87799 impacts LXD 4.0+ and the btrfs flaw affects 4.0.2+, with fixed releases listed as 4.0.14, 5.0.10, 5.21.8 and 6.10 (and a 6.9 build at a defined commit); optimized ZFS transfers are not affected.

  • Severity rankings place CVE-2026-87799 and CVE-2026-85526 at 9.9, and CVE-2026-85185 at 9.6, with public proof-of-concept available for the symlink issue.

  • The advisory emphasizes exposure context, urging operators to consider systems that may have imported unpatched backups, and recommends preserving logs or memory dumps before patching for forensic purposes.

  • The article points readers to external advisories and analyses for additional context and deeper technical details.

Summary based on 1 source


Get a daily email with more Tech stories

More Stories