Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-63293

Опубликовано: 12 авг. 2026
Источник: debian
EPSS Низкий

Описание

A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate whether the metadata.yaml file is a symbolic link. An attacker can exploit this flaw by providing a crafted image archive with a symlinked metadata.yaml file pointing to target file paths on the host system.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
lxdremovedpackage
lxdend-of-lifebookwormpackage

Примечания

  • https://github.com/canonical/lxd/security/advisories/GHSA-j825-cg34-5fr5

EPSS

Процентиль: 31%
0.00382
Низкий

Связанные уязвимости

CVSS3: 9.9
ubuntu
22 дня назад

A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate whether the metadata.yaml file is a symbolic link. An attacker can exploit this flaw by providing a crafted image archive with a symlinked metadata.yaml file pointing to target file paths on the host system.

CVSS3: 9.9
nvd
22 дня назад

A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate whether the metadata.yaml file is a symbolic link. An attacker can exploit this flaw by providing a crafted image archive with a symlinked metadata.yaml file pointing to target file paths on the host system.

EPSS

Процентиль: 31%
0.00382
Низкий