CVE-2026-85185

EUVD-2026-88258
Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete arbitrary files on the host as root. On hosts whose root filesystem is btrfs, the client can also place attacker-controlled content at arbitrary host paths, leading to full host compromise. The client does this with a crafted subvolume path containing ../ sequences, sent in either of two ways: in the optimized_header.yaml of an optimized btrfs backup, or in the btrfs migration header sent by a malicious migration source.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
canonicalCNA
9.6 CRITICAL
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
canonicallxd
4.0.2 ≤
𝑥
< 4.0.14
CNA
canonicallxd
5.0.0 ≤
𝑥
< 5.0.10
CNA
canonicallxd
5.21.0 ≤
𝑥
< 5.21.8
CNA
canonicallxd
6.0 ≤
𝑥
< 6.10
CNA
Debian logo
Debian Releases
Debian Product
Codename
incus
forky
vulnerable
sid
7.0.1-5
fixed
trixie
vulnerable
trixie (security)
6.0.4-2+deb13u11
fixed
lxd
bookworm
vulnerable
bookworm (security)
vulnerable
trixie
vulnerable
trixie (security)
vulnerable