---
id: CVE-2026-9639
title: >-
  Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version
  6.8 and 5.21 on Linux allows an authenticated user with
  can_create_storage_volumes permissions to cause a denial of service via a
  specially crafted custom-volum…
summary: >-
  Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version
  6.8 and 5.21 on Linux allows an authenticated user with
  can_create_storage_volumes permissions to cause a denial of service via a
  specially crafted custom-volum…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-476
vendor: canonical
product: lxd
affected:
  - 'lxd >= 5.0.0, < 5.21.5'
  - 'lxd >= 6.0, < 6.9'
patched:
  - lxd 6.9
published: '2026-06-26'
updated: '2026-07-02'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-9639'
references:
  - url: 'https://github.com/canonical/lxd/pull/18320'
    label: security@ubuntu.com
  - url: 'https://github.com/canonical/lxd/pull/18390'
    label: security@ubuntu.com
  - url: 'https://github.com/canonical/lxd/security/advisories/GHSA-j93m-3j9p-m5m8'
    label: security@ubuntu.com
  - url: 'https://github.com/canonical/lxd/security/advisories/GHSA-j93m-3j9p-m5m8'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00548
epssPercentile: 0.44565
ingestedAt: '2026-07-03T13:02:28.085Z'
---

## Overview

Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted custom-volume backup tarball that omits the expires_at snapshot field.

## Affected

- `lxd >= 5.0.0, < 5.21.5`
- `lxd >= 6.0, < 6.9`

## Remediation

Upgrade past the affected range:

- `lxd 6.9`
