Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-12411

Опубликовано: 26 июн. 2026
Источник: debian

Описание

Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when security.devlxd.management.volumes is enabled.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
lxdnot-affectedpackage

Примечания

  • https://github.com/canonical/lxd/security/advisories/GHSA-hhf9-qw4v-72xp

  • https://github.com/canonical/lxd/pull/18585

Связанные уязвимости

CVSS3: 8.4
ubuntu
2 месяца назад

Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when security.devlxd.management.volumes is enabled.

CVSS3: 8.4
nvd
2 месяца назад

Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when security.devlxd.management.volumes is enabled.