CVE-2026-63297: Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge
An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a target project, LXD performs restriction checks before configuration merging is complete, creating a time-of-check to time-of-use (TOCTOU) condition. An attacker can exploit this flaw to copy instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
LXDto a version that resolves this vulnerability.Fixed in 5.0.8 - Upgrade
Upgrade
LXDto a version that resolves this vulnerability.Fixed in 5.12.6
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63297?
CVE-2026-63297 has a critical severity rating of 9.9.
How do I fix CVE-2026-63297?
To fix CVE-2026-63297, you should update Canonical LXD to the latest version that addresses this vulnerability.
Who is affected by CVE-2026-63297?
Affected users are primarily those utilizing Canonical LXD in environments where cross-project instance copying occurs.
What type of vulnerability is CVE-2026-63297?
CVE-2026-63297 is an authorization bypass vulnerability caused by a timing flaw in configuration merging.
Can CVE-2026-63297 be exploited remotely?
Yes, CVE-2026-63297 can be exploited by an authenticated attacker with access to the LXD service.