DEBIAN-CVE-2026-34177

Source
https://security-tracker.debian.org/tracker/CVE-2026-34177
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-34177.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-34177
Upstream
Published
2026-04-09T10:16:21Z
Modified
2026-09-14T17:03:08Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limits/permissions.go), which omits raw.apparmor and raw.qemu.conf from the set of keys blocked under the restricted.virtual-machines.lowlevel=block project restriction. A remote attacker with can_edit permission on a VM instance in a restricted project can inject an AppArmor rule and a QEMU chardev configuration that bridges the LXD Unix socket into the guest VM, enabling privilege escalation to LXD cluster administrator and subsequently to host root.

References

Affected packages

Debian:13 / incus

Package

Name
incus
Purl
pkg:deb/debian/incus?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
6.0.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-34177.json"

Debian:14 / incus

Package

Name
incus
Purl
pkg:deb/debian/incus?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
6.0.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-34177.json"

Debian:12 / lxd

Package

Name
lxd
Purl
pkg:deb/debian/lxd?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

5.*
5.0.2-5
5.0.2-5+deb12u1
5.0.2-5+deb12u2
5.0.2-5+deb12u3
5.0.2-5+deb12u4
5.0.2-5+deb12u5
5.0.2-5+deb12u6
5.0.2-6
5.0.2+git20231211.1364ae4-1
5.0.2+git20231211.1364ae4-2
5.0.2+git20231211.1364ae4-3
5.0.2+git20231211.1364ae4-4
5.0.2+git20231211.1364ae4-5
5.0.2+git20231211.1364ae4-6
5.0.2+git20231211.1364ae4-7
5.0.2+git20231211.1364ae4-8
5.0.2+git20231211.1364ae4-9

Ecosystem specific

{
    "urgency": "end-of-life"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-34177.json"

Debian:13 / lxd

Package

Name
lxd
Purl
pkg:deb/debian/lxd?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.0.2+git20231211.1364ae4-9+deb13u5

Affected versions

5.*
5.0.2+git20231211.1364ae4-9
5.0.2+git20231211.1364ae4-9+deb13u1
5.0.2+git20231211.1364ae4-9+deb13u2
5.0.2+git20231211.1364ae4-9+deb13u3
5.0.2+git20231211.1364ae4-9+deb13u4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-34177.json"