Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-9639

Опубликовано: 26 июн. 2026
Источник: debian
EPSS Низкий

Описание

Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted custom-volume backup tarball that omits the expires_at snapshot field.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
lxdremovedpackage
lxdend-of-lifebookwormpackage

Примечания

  • https://github.com/canonical/lxd/security/advisories/GHSA-j93m-3j9p-m5m8

  • https://github.com/canonical/lxd/pull/18320

  • https://github.com/canonical/lxd/pull/18390

EPSS

Процентиль: 29%
0.00376
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 месяца назад

Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted custom-volume backup tarball that omits the expires_at snapshot field.

CVSS3: 6.5
nvd
около 1 месяца назад

Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted custom-volume backup tarball that omits the expires_at snapshot field.

EPSS

Процентиль: 29%
0.00376
Низкий