Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.
https://www.cve.org/CVERecord?id=CVE-2024-6219
https://github.com/canonical/lxd/security/advisories/GHSA-jpmc-7p9c-4rxf