—
GO-2025-4121
LXD vulnerable to a local privilege escalation through custom storage volumes in lxd in github.com/canonical/lxd
Details
LXD vulnerable to a local privilege escalation through custom storage volumes in lxd in github.com/canonical/lxd
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/canonical/lxd
Introduced in:
0No fixed version published yet for github.com/canonical/lxd (go modules). Pin to a known-safe version or switch to an alternative.
References
- https://github.com/canonical/lxd/security/advisories/GHSA-3g2j-vm47-x4mj[ADVISORY]
- https://github.com/canonical/lxd/pull/16904[FIX]
- https://github.com/canonical/lxd/pull/16922[FIX]
- https://github.com/canonical/lxd/pull/16923[FIX]
- https://github.com/canonical/lxd/pull/16924[FIX]
- https://github.com/lxc/incus/issues/2641[WEB]
- https://github.com/lxc/incus/security/advisories/GHSA-56mx-8g9f-5crf[WEB]