Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-66898

Опубликовано: 12 авг. 2026
Источник: debian
EPSS Низкий

Описание

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive with malicious instance or volume names containing path traversal sequences, potentially allowing file access or overwriting outside the designated restore directory.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
lxdremovedpackage
lxdend-of-lifebookwormpackage

Примечания

  • https://github.com/canonical/lxd/security/advisories/GHSA-m857-c7gc-c984

EPSS

Процентиль: 27%
0.00344
Низкий

Связанные уязвимости

CVSS3: 9.9
ubuntu
20 дней назад

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive with malicious instance or volume names containing path traversal sequences, potentially allowing file access or overwriting outside the designated restore directory.

CVSS3: 9.9
nvd
20 дней назад

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive with malicious instance or volume names containing path traversal sequences, potentially allowing file access or overwriting outside the designated restore directory.

EPSS

Процентиль: 27%
0.00344
Низкий