CVE-2026-63297

EUVD-2026-57513
An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a target project, LXD performs restriction checks before configuration merging is complete, creating a time-of-check to time-of-use (TOCTOU) condition. An attacker can exploit this flaw to copy instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.
TOCTOU
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.9 CRITICAL
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 25.26%
Affected Products (NVD)
VendorProductVersion
canonicallxd
5.0.0 ≤
𝑥
< 5.0.8
canonicallxd
5.1 ≤
𝑥
< 5.21.6
canonicallxd
6.0 ≤
𝑥
< 6.9
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
lxd
bookworm
vulnerable
bookworm (security)
vulnerable
trixie
vulnerable
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
lxd
bionic
needs-triage
focal
needs-triage
jammy
dne
noble
dne
resolute
dne
xenial
needs-triage