Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-28384

Опубликовано: 12 мар. 2026
Источник: ubuntu
Приоритет: medium

Описание

An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup endpoints. This issue affected LXD from 4.12 through 6.6 and was fixed in the snap versions 5.0.6-e49d9f4 (channel 5.0/stable), 5.21.4-1374f39 (channel 5.21/stable), and 6.7-1f11451 (channel 6.0 stable). The channel 4.0/stable is not affected as it contains version 4.0.10.

РелизСтатусПримечание
devel

DNE

esm-apps/focal

not-affected

1:0.10
esm-infra/bionic

not-affected

3.0.3-0ubuntu1~18.04.2+esm1
esm-infra/xenial

not-affected

2.0.11-0ubuntu1~16.04.4+esm1
jammy

DNE

noble

DNE

questing

DNE

upstream

released

6.7

Показывать по

Связанные уязвимости

nvd
18 дней назад

An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup endpoints. This issue affected LXD from 4.12 through 6.6 and was fixed in the snap versions 5.0.6-e49d9f4 (channel 5.0/stable), 5.21.4-1374f39 (channel 5.21/stable), and 6.7-1f11451 (channel 6.0 stable). The channel 4.0/stable is not affected as it contains version 4.0.10.

debian
18 дней назад

An improper sanitization of the compression_algorithm parameter in Can ...