CVE-2026-85526: Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipulation in LXD

Published Sep 28, 2026
·
Updated

Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root via a crafted subvolumes[].path entry in backup/optimizedheader.yaml during a btrfs optimized backup import.

Affected Software

1 affected component
Canonical LXD

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Canonical LXD to a version that resolves this vulnerability.

    Fixed in 4.0.14

Event History

Sep 28, 2026
CVE Published
via MITRE·01:21 PM
Data Sourced
via MITRE·01:21 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Can an unauthenticated remote attacker exploit this issue?

No. Exploitation requires an authenticated LXD user with privileges to create instances.

2

What environment and operation are required for exploitation?

The affected workflow is importing a Btrfs optimized backup. The attacker must provide a crafted subvolumes[].path entry in the backup's optimized_header.yaml file.

3

What is the impact on the host if exploitation succeeds?

The attacker can cause arbitrary host files and directories to be deleted or replaced. These operations occur with root privileges.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203