Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-12411

Опубликовано: 26 июн. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 8.4

Описание

Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when security.devlxd.management.volumes is enabled.

РелизСтатусПримечание
devel

DNE

esm-apps/focal

not-affected

code not present
esm-infra-legacy/xenial

not-affected

code not present
esm-infra/bionic

not-affected

code not present
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

not-affected

debian: Only affects LXD 6.6 and later

Показывать по

8.4 High

CVSS3

Связанные уязвимости

CVSS3: 8.4
nvd
2 месяца назад

Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when security.devlxd.management.volumes is enabled.

CVSS3: 8.4
debian
2 месяца назад

Broken Access Control in the devLXDInstancePatchHandler component of C ...

8.4 High

CVSS3