CVE-2026-63298: LXD arbitrary lxc.conf directive injection via NVIDIA instance configuration
An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline characters within the 'nvidia.driver.capabilities' or 'nvidia.require.' configuration values, an attacker can manipulate the generated lxc.conf file. This flaw enables the attacker to execute arbitrary code on the host system with the privileges of the LXD daemon.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.0.12 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.0.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.12.6
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63298?
CVE-2026-63298 has a high severity rating of 8.7.
How do I fix CVE-2026-63298?
To fix CVE-2026-63298, ensure you upgrade LXD to the latest version that addresses this vulnerability.
What types of attacks can exploit CVE-2026-63298?
CVE-2026-63298 can be exploited by authenticated attackers to inject arbitrary configuration directives.
What impact does CVE-2026-63298 have on system security?
CVE-2026-63298 can lead to command injection allowing attackers to compromise the confidentiality, integrity, and availability of the system.
Who is affected by CVE-2026-63298?
CVE-2026-63298 affects users of LXD with an NVIDIA configuration that allows for the injection of arbitrary directives.