CVE-2026-9639Medium· 6.5▾ SunlitNil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted custom-volum…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
0.4% → 0.5%
Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted custom-volume backup tarball that omits the expires_at snapshot field.
lxd >= 5.0.0, < 5.21.5lxd >= 6.0, < 6.9Upgrade past the affected range:
lxd 6.9Connected by shared product, vendor, weakness, or advisory.
CVE-2026-66897Critical· 9.9A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root
CVE-2026-63297Critical· 9.9An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies
CVE-2026-16033High· 8.5A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation
CVE-2026-63298Critical· 9.9An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives
CVE-2026-63299Critical· 9.9An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits
CVE-2026-63300Critical· 9.9An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level security res…