CVE-2026-63293: Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root
A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate whether the metadata.yaml file is a symbolic link. An attacker can exploit this flaw by providing a crafted image archive with a symlinked metadata.yaml file pointing to target file paths on the host system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.0.12 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.0.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.12.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.10
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63293?
CVE-2026-63293 has a critical severity rating of 9.9.
How do I fix CVE-2026-63293?
To fix CVE-2026-63293, update Canonical LXD to the latest patched version eliminating the symbolic link vulnerability.
What impact does CVE-2026-63293 have on my system?
CVE-2026-63293 allows arbitrary file read and write operations on the host filesystem, potentially giving attackers root access.
Who is affected by CVE-2026-63293?
Users of Canonical LXD who utilize image archives are affected by CVE-2026-63293 due to the lack of validation for symbolic links.
When was CVE-2026-63293 published?
CVE-2026-63293 was published on August 12, 2026.