CVE-2026-28384: Authenticated RCE via unsanitized compression_algorithm
An improper sanitization of the compressionalgorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup endpoints. This issue affected LXD from 4.12 through 6.6 and was fixed in the snap versions 5.0.6-e49d9f4 (channel 5.0/stable), 5.21.4-1374f39 (channel 5.21/stable), and 6.7-1f11451 (channel 6.0 stable). The channel 4.0/stable is not affected as it contains version 4.0.10.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Canonical LXDto a version that resolves this vulnerability.Fixed in 5.0.6-e49d9f4 - Upgrade
Upgrade
Canonical LXDto a version that resolves this vulnerability.Fixed in 5.21.4-1374f39 - Upgrade
Upgrade
Canonical LXDto a version that resolves this vulnerability.Fixed in 6.7-1f11451
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28384?
CVE-2026-28384 has been classified as a critical vulnerability due to its ability to allow authenticated remote code execution.
How do I fix CVE-2026-28384?
To fix CVE-2026-28384, update your LXD installation to version 6.6 or later.
Who is affected by CVE-2026-28384?
CVE-2026-28384 affects users of Canonical LXD versions 4.12 up to 6.6 who have unprivileged authentication.
What is the impact of CVE-2026-28384?
The impact of CVE-2026-28384 allows an authenticated, unprivileged attacker to execute commands as the LXD daemon.
What are the vulnerable components related to CVE-2026-28384?
The vulnerable component related to CVE-2026-28384 is the compression_algorithm parameter in Canonical LXD.