Critical LXD Security Flaws Expose Multi-Tenant Hosts to Compromise; Urgent Patch Required
October 1, 2026
The report centers on CVE-2026-87799 and related LXD backup/import security flaws, showing how migration and restore processes can be exploited to achieve host-level compromise in multi-tenant environments.
Two exploitation paths are described: on migration, streams handed to rsync or btrfs receive can allow symlink traversal; on restore, an attacker-supplied backup header can steer subvolume paths to escape the destination volume.
Hardening guidance includes upgrading to fixed releases, restricting import paths to trusted identities, only accepting migrations from controlled servers, avoiding btrfs-optimized backups from untrusted sources, and limiting backup import for non-admins in multi-tenant setups until upgrades are complete.
Affected versions are specified: CVE-2026-87799 impacts LXD 4.0+ and the btrfs flaw affects 4.0.2+, with fixed releases listed as 4.0.14, 5.0.10, 5.21.8 and 6.10 (and a 6.9 build at a defined commit); optimized ZFS transfers are not affected.
Severity rankings place CVE-2026-87799 and CVE-2026-85526 at 9.9, and CVE-2026-85185 at 9.6, with public proof-of-concept available for the symlink issue.
The advisory emphasizes exposure context, urging operators to consider systems that may have imported unpatched backups, and recommends preserving logs or memory dumps before patching for forensic purposes.
The article points readers to external advisories and analyses for additional context and deeper technical details.
Summary based on 1 source
Get a daily email with more Tech stories
Source

DEV Community • Oct 1, 2026
LXD Backup Import as an Attack Surface: CVE-2026-87799 and the btrfs Restore Path