← Zuruck zu CVEs
CVE-2026-34177
CRITICAL9.1
Beschreibung
Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limits/permissions.go), which omits raw.apparmor and raw.qemu.conf from the set of keys blocked under the restricted.virtual-machines.lowlevel=block project restriction. A remote attacker with can_edit permission on a VM instance in a restricted project can inject an AppArmor rule and a QEMU chardev configuration that bridges the LXD Unix socket into the guest VM, enabling privilege escalation to LXD cluster administrator and subsequently to host root.
CVE Details
CVSS v3.1 Bewertung9.1
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienHIGH
BenutzerinteraktionNONE
Veroffentlicht4/9/2026
Zuletzt geandert4/13/2026
Quellenvd
Honeypot-Sichtungen0
Schwachen (CWE)
CWE-184
Referenzen
https://github.com/canonical/lxd/pull/17909(security@ubuntu.com)
https://github.com/canonical/lxd/security/advisories/GHSA-fm2x-c5qw-4h6f(security@ubuntu.com)
https://github.com/canonical/lxd/security/advisories/GHSA-fm2x-c5qw-4h6f(134c704f-9b21-4f2e-91b3-4a467353bcc0)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.