EUVD Vulnerability Catalog
EUVD-2026-88257
Severity: CRITICAL
Base Score: 9.9
CVSS Version: 3.1
Vulnerability Description
Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root via a crafted subvolumes[].path entry in backup/optimized_header.yaml during a btrfs optimized backup import.
CVSS Vector Analysis
Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
▪
Attack Vector (AV): Network
▪
Attack Complexity (AC): Low
▪
Privileges Required (PR): Low
▪
User Interaction (UI): None
▪
Scope (S): Changed
▪
Confidentiality Impact (C): High
▪
Integrity Impact (I): High
▪
Availability Impact (A): High
Affected Vendors & Systems
Vendor
Canonical
References & Advisory Links
- https://github.com/canonical/lxd/security/advisories/GHSA-h85r-gjgx-g2rv
- https://github.com/canonical/lxd-private/pull/87
- https://github.com/canonical/lxd-private/pull/105
- https://github.com/canonical/lxd-private/pull/104
- https://github.com/canonical/lxd-private/pull/103
- https://github.com/canonical/lxd-private/pull/84
Metadata Profile
Database Authority
European Union Agency for Cybersecurity (ENISA) EUVD
Assigner
canonical
EPSS Probability
0
Known Aliases
CVE-2026-85526
Published On
2026-09-28
Last Updated
2026-09-28