CVE-2026-85526

critical

Description

Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root via a crafted subvolumes[].path entry in backup/optimized_header.yaml during a btrfs optimized backup import.

References

https://github.com/canonical/lxd/security/advisories/GHSA-h85r-gjgx-g2rv

https://github.com/canonical/lxd-private/pull/87

https://github.com/canonical/lxd-private/pull/84

https://github.com/canonical/lxd-private/pull/105

https://github.com/canonical/lxd-private/pull/104

https://github.com/canonical/lxd-private/pull/103

Details

Source: Mitre, NVD

Published: 2026-09-28

Updated: 2026-09-29

Risk Information

CVSS v2

Base Score: 9

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 9.9

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.00516