CVE-2026-63298

Source
https://cve.org/CVERecord?id=CVE-2026-63298
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63298.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63298
Aliases
  • GHSA-vfh7-q59q-54v2
Downstream
Published
2026-08-12T19:22:07.286Z
Modified
2026-08-15T11:31:05.310562296Z
Severity
  • 9.9 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
LXD arbitrary lxc.conf directive injection via NVIDIA instance configuration
Details

An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline characters within the 'nvidia.driver.capabilities' or 'nvidia.require.*' configuration values, an attacker can manipulate the generated lxc.conf file. This flaw enables the attacker to execute arbitrary code on the host system with the privileges of the LXD daemon.

Database specific
{
    "cwe_ids": [
        "CWE-78"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63298.json",
    "cna_assigner": "canonical"
}
References

Affected packages

Git / github.com/canonical/lxd

Affected ranges

Type
GIT
Repo
https://github.com/canonical/lxd
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "5.0.0"
        },
        {
            "fixed": "5.0.8"
        },
        {
            "introduced": "5.21.0"
        },
        {
            "fixed": "5.21.6"
        },
        {
            "introduced": "4.0.0"
        },
        {
            "fixed": "4.0.12"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

lxd-4.*
lxd-4.0.0
lxd-4.0.1
lxd-4.0.11
lxd-4.0.2
lxd-4.0.3
lxd-4.0.4
lxd-4.0.5
lxd-4.0.6
lxd-4.0.7
lxd-4.0.8
lxd-4.0.9
lxd-5.*
lxd-5.0.0
lxd-5.0.1
lxd-5.0.2
lxd-5.0.7
lxd-5.1
lxd-5.10
lxd-5.11
lxd-5.12
lxd-5.13
lxd-5.14
lxd-5.15
lxd-5.16
lxd-5.17
lxd-5.2
lxd-5.21.5
lxd-5.3
lxd-5.4
lxd-5.5
lxd-5.6
lxd-5.7
lxd-5.8
lxd-5.9
Other
show

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63298.json"