CVE-2026-63294: Root RCE via image backup.yaml symlink
A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and confine the backup.yaml file when it exists as a symbolic link. An attacker can exploit this flaw by providing a malicious archive with a symlinked backup.yaml file, causing LXD to process unconfined configuration metadata and execute arbitrary commands with root privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.0.12 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.0.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.12.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.10
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63294?
CVE-2026-63294 has a critical severity rating of 9.9.
How does CVE-2026-63294 impact the system?
CVE-2026-63294 allows an attacker to achieve root command execution on the host system.
How can I mitigate CVE-2026-63294?
To mitigate CVE-2026-63294, ensure that LXD software is updated to the latest version that addresses this vulnerability.
What is the nature of the vulnerability in CVE-2026-63294?
CVE-2026-63294 is a link following vulnerability related to the improper handling of the backup.yaml file as a symbolic link.
What software is affected by CVE-2026-63294?
CVE-2026-63294 affects the Canonical LXD software.