云虫漏洞库

CVE-2026-63294 - A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and confine the backup.yaml file when it exists as a symbolic link. An attacker can exploit this flaw by providing a malicious archive with a symlinked backup.yaml file, causing LXD to process unconfined configuration metadata and execute arbitrary commands with root privi - 漏洞详情

漏洞编号:CVE-2026-63294

风险等级:危急

漏洞来源:CVE

CVE 编号:CVE-2026-63294

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-59

发布/更新时间:2026-08-12 / 2026-08-28

漏洞描述

A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and confine the backup.yaml file when it exists as a symbolic link. An attacker can exploit this flaw by providing a malicious archive with a symlinked backup.yaml file, causing LXD to process unconfined configuration metadata and execute arbitrary commands with root privileges.

相关链接

相关漏洞

« 返回首页