CVE-2026-87798: LXD client recursive file pull allows directory escape via malicious VM agent
Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.0.2 up to 6.9 (fixed in 4.0.14, 5.0.10 and 5.21.8) on Linux allows an attacker with root access inside a virtual machine to write attacker-controlled files or directory trees to arbitrary paths on the client host, with the operator's privileges. The attacker does this by using a modified lxd-agent that returns inconsistent SFTP directory listings and Lstat results.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Canonical LXDto a version that resolves this vulnerability.Fixed in 4.0.14 - Upgrade
Upgrade
Canonical LXDto a version that resolves this vulnerability.Fixed in 5.0.10 - Upgrade
Upgrade
Canonical LXDto a version that resolves this vulnerability.Fixed in 5.21.8
Event History
Frequently Asked Questions
Who is exposed to this issue?
Linux operators using an affected LXD CLI version are exposed when they recursively pull files from a virtual machine whose in-guest agent is controlled by an attacker. The attacker needs root access inside that VM to replace or modify the lxd-agent behavior.
What interaction is required for exploitation?
An operator must use the LXD CLI recursive file pull feature against the malicious VM. The attack relies on the agent returning inconsistent SFTP directory-listing and Lstat results during that pull.
What is the impact on the client host?
A successful attack can cause attacker-controlled files or directory trees to be written to arbitrary paths on the client host. Writes occur with the privileges of the operator running the LXD CLI.
Which versions contain fixes?
Canonical identifies fixes in LXD 4.0.14, 5.0.10, and 5.21.8. The affected version ranges are 4.0.2 through 6.9.