CVE-2026-9639
EUVD-2026-3978926.06.2026, 16:16
Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted custom-volume backup tarball that omits the expires_at snapshot field.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| canonical | lxd | 5.0.0 ≤ 𝑥 < 5.21.5 |
| canonical | lxd | 6.0 ≤ 𝑥 < 6.9 |
𝑥
= Vulnerable software versions
Debian Releases
Common Weakness Enumeration