云虫漏洞库

CVE-2026-63298 - An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline characters within the 'nvidia.driver.capabilities' or 'nvidia.require.*' configuration values, an attacker can manipulate the generated lxc.conf file. This flaw enables the attacker to execute arbitrary code on the host system with the privileges of the LXD daemon. - 漏洞详情

漏洞编号:CVE-2026-63298

风险等级:危急

漏洞来源:CVE

CVE 编号:CVE-2026-63298

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-78

发布/更新时间:2026-08-12 / 2026-08-28

漏洞描述

An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline characters within the 'nvidia.driver.capabilities' or 'nvidia.require.*' configuration values, an attacker can manipulate the generated lxc.conf file. This flaw enables the attacker to execute arbitrary code on the host system with the privileges of the LXD daemon.

相关链接

相关漏洞

« 返回首页