Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to LXD version 5.21.5 or later, or 6.9 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 26 Jun 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canonical
Canonical lxd |
|
| Vendors & Products |
Canonical
Canonical lxd |
Fri, 26 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 26 Jun 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted custom-volume backup tarball that omits the expires_at snapshot field. | |
| Title | Authenticated Denial of Service via Malicious Backup Tarball in LXD | |
| Weaknesses | CWE-476 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2026-06-26T16:02:11.520Z
Reserved: 2026-05-26T18:31:05.985Z
Link: CVE-2026-9639
Updated: 2026-06-26T16:02:07.362Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-26T23:00:08Z