Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21788-1

Опубликовано: 02 сент. 2026
Источник: suse-cvrf

Описание

Security update for lxd

This update for lxd fixes the following issues:

Changes in lxd:

Список пакетов

openSUSE Leap 16.0
lxd-5.21.6-bp160.1.1
lxd-bash-completion-5.21.6-bp160.1.1

Описание

Buffer Overflow vulnerability in osrg gobgp commit 419c50dfac578daa4d11256904d0dc182f1a9b22 allows a remote attacker to cause a denial of service via the handlingError function in pkg/server/fsm.go.


Затронутые продукты
openSUSE Leap 16.0:lxd-5.21.6-bp160.1.1
openSUSE Leap 16.0:lxd-bash-completion-5.21.6-bp160.1.1

Ссылки

Описание

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member via POST /1.0/instances/{name} with migration: true, project: <target>, and target: <member>, the destination node skips all project restriction checks because the request arrives as an internal cluster notification. An attacker can exploit this to introduce disallowed instance configurations into a restricted project.


Затронутые продукты
openSUSE Leap 16.0:lxd-5.21.6-bp160.1.1
openSUSE Leap 16.0:lxd-bash-completion-5.21.6-bp160.1.1

Ссылки

Описание

A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate whether the metadata.yaml file is a symbolic link. An attacker can exploit this flaw by providing a crafted image archive with a symlinked metadata.yaml file pointing to target file paths on the host system.


Затронутые продукты
openSUSE Leap 16.0:lxd-5.21.6-bp160.1.1
openSUSE Leap 16.0:lxd-bash-completion-5.21.6-bp160.1.1

Ссылки

Описание

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions. When a project is configured with restrictions on container privileges (such as enforcing restricted.containers.privilege=isolated), LXD fails to enforce the requirement if an instance configuration omits the security.idmap.isolated key. An attacker can exploit this flaw by creating or updating an instance without explicitly setting security.idmap.isolated, bypassing the target project's security constraints.


Затронутые продукты
openSUSE Leap 16.0:lxd-5.21.6-bp160.1.1
openSUSE Leap 16.0:lxd-bash-completion-5.21.6-bp160.1.1

Ссылки

Описание

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the target project's enforced restrictions. An attacker can exploit this flaw to move instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.


Затронутые продукты
openSUSE Leap 16.0:lxd-5.21.6-bp160.1.1
openSUSE Leap 16.0:lxd-bash-completion-5.21.6-bp160.1.1

Ссылки

Описание

An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a target project, LXD performs restriction checks before configuration merging is complete, creating a time-of-check to time-of-use (TOCTOU) condition. An attacker can exploit this flaw to copy instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.


Затронутые продукты
openSUSE Leap 16.0:lxd-5.21.6-bp160.1.1
openSUSE Leap 16.0:lxd-bash-completion-5.21.6-bp160.1.1

Ссылки

Описание

An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline characters within the 'nvidia.driver.capabilities' or 'nvidia.require.*' configuration values, an attacker can manipulate the generated lxc.conf file. This flaw enables the attacker to execute arbitrary code on the host system with the privileges of the LXD daemon.


Затронутые продукты
openSUSE Leap 16.0:lxd-5.21.6-bp160.1.1
openSUSE Leap 16.0:lxd-bash-completion-5.21.6-bp160.1.1

Ссылки

Описание

An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource limits during volume operations: the storagePoolVolumeTypePostMove function omits the limits.AllowVolumeCreation check before moving a volume across projects, and volume snapshot restore operations skip the AllowVolumeUpdate check when the configuration is nil (Config == nil). An attacker can exploit these flaws to allocate storage resources that exceed the administrative limits configured for a project.


Затронутые продукты
openSUSE Leap 16.0:lxd-5.21.6-bp160.1.1
openSUSE Leap 16.0:lxd-bash-completion-5.21.6-bp160.1.1

Ссылки

Описание

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive with malicious instance or volume names containing path traversal sequences, potentially allowing file access or overwriting outside the designated restore directory.


Затронутые продукты
openSUSE Leap 16.0:lxd-5.21.6-bp160.1.1
openSUSE Leap 16.0:lxd-bash-completion-5.21.6-bp160.1.1

Ссылки