CVE-2026-9639
EUVD-2026-3978926.06.2026, 16:16
Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted custom-volume backup tarball that omits the expires_at snapshot field.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| canonical | lxd | 5.21.0 ≤ 𝑥 < 5.21.5 | CNA |
| canonical | lxd | 6.0 ≤ 𝑥 < 6.9 | CNA |
Common Weakness Enumeration