CVE-2026-12411

Published Jun 26, 2026

Last updated 21 days ago

Overview

Description
Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when security.devlxd.management.volumes is enabled.
Source
security@ubuntu.com
NVD status
Analyzed
Products
lxd

Risk scores

CVSS 3.1

Type
Primary
Base score
9.6
Impact score
5.8
Exploitability score
3.1
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Severity
CRITICAL

Weaknesses

security@ubuntu.com
CWE-639

Social media

Hype score
Not currently trending

Configurations