CVE-2026-85185
Deferred Deferred - Pending Action

Path Traversal in Canonical LXD Storage Driver

Vulnerability report for CVE-2026-85185, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: Canonical Ltd.

Description

Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete arbitrary files on the host as root. On hosts whose root filesystem is btrfs, the client can also place attacker-controlled content at arbitrary host paths, leading to full host compromise. The client does this with a crafted subvolume path containing ../ sequences, sent in either of two ways: in the optimized_header.yaml of an optimized btrfs backup, or in the btrfs migration header sent by a malicious migration source.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
canonical lxd From 4.0.2 (inc)
canonical lxd to 4.0.14 (inc)
canonical lxd to 5.0.10 (inc)
canonical lxd to 5.21.8 (inc)
canonical lxd to 6.10 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-85185 is a path traversal vulnerability in Canonical LXD's btrfs storage driver. It allows an authenticated user with project creation permissions to delete arbitrary files on the host as root or place attacker-controlled content at arbitrary host paths. This occurs due to unvalidated subvolume paths in backup restoration or migration operations, enabling path traversal sequences like ../../../ to escape the storage pool.

Detection Guidance

To detect this vulnerability, check LXD versions for affected releases (4.0.2 to 4.0.13, 5.0.1 to 5.0.9, 5.21.1 to 5.21.7, 6.1 to 6.9). Inspect logs for unusual backup or migration operations involving btrfs subvolume paths with ../ sequences. Use commands like 'lxd --version' to verify versions and 'journalctl -u lxd' to review logs for suspicious activities.

Impact Analysis

If you use LXD with btrfs storage, an attacker with project access could delete critical system files or install malicious code on your host. On systems where the root filesystem is btrfs, this could lead to full host compromise, including remote code execution. The attack requires only project-restricted access and no user interaction.

Compliance Impact

This vulnerability could lead to unauthorized data access, modification, or deletion, violating GDPR's integrity and confidentiality principles or HIPAA's security requirements for protected health information. Full host compromise may result in data breaches, triggering mandatory breach notifications under these regulations.

Mitigation Strategies

Immediately upgrade LXD to patched versions (4.0.14, 5.0.10, 5.21.8, 6.10 or later). Disable project-restricted users' ability to create instances or perform backups/migration until patched. Review and restrict access to LXD instances, especially those using btrfs storage pools. Monitor for unauthorized file changes or deletions on the host.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85185. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart