CVE-2026-87798

Source
https://cve.org/CVERecord?id=CVE-2026-87798
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-87798.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-87798
Aliases
  • GHSA-mr8v-hx34-hfvf
Downstream
Published
2026-09-28T13:22:36Z
Modified
2026-09-30T03:47:28Z
Severity
  • 5.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:N CVSS Calculator
Summary
LXD client recursive file pull allows directory escape via malicious VM agent
Details

Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.0.2 up to 6.9 (fixed in 4.0.14, 5.0.10 and 5.21.8) on Linux allows an attacker with root access inside a virtual machine to write attacker-controlled files or directory trees to arbitrary paths on the client host, with the operator's privileges. The attacker does this by using a modified lxd-agent that returns inconsistent SFTP directory listings and Lstat results.

Database specific
{
    "cna_assigner":  "canonical",
    "cwe_ids":  [
        "CWE-59"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/87xxx/CVE-2026-87798.json"
}
References

Affected packages

Git / github.com/canonical/lxd

Affected ranges

Type
GIT
Repo
https://github.com/canonical/lxd
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "4.0.2"
        },
        {
            "fixed":  "4.0.14"
        },
        {
            "introduced":  "5.0.0"
        },
        {
            "fixed":  "5.0.10"
        },
        {
            "introduced":  "5.21.0"
        },
        {
            "fixed":  "5.21.8"
        },
        {
            "introduced":  "6.0"
        },
        {
            "fixed":  "6.9"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

lxd-4.*
lxd-4.0.11
lxd-4.0.12
lxd-4.0.13
lxd-4.0.2
lxd-4.0.3
lxd-4.0.4
lxd-4.0.5
lxd-4.0.6
lxd-4.0.7
lxd-4.0.8
lxd-4.0.9
lxd-5.*
lxd-5.0.0
lxd-5.0.1
lxd-5.0.2
lxd-5.0.7
lxd-5.0.8
lxd-5.0.9
lxd-5.1
lxd-5.10
lxd-5.11
lxd-5.12
lxd-5.13
lxd-5.14
lxd-5.15
lxd-5.16
lxd-5.17
lxd-5.2
lxd-5.21.5
lxd-5.21.6
lxd-5.21.7
lxd-5.3
lxd-5.4
lxd-5.5
lxd-5.6
lxd-5.7
lxd-5.8
lxd-5.9
lxd-6.*
lxd-6.8
Other
show

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-87798.json"