Skip to content
TopicTracker
From HackerNewsView original
TranslationTranslation

Six critical 9.9-CVSS vulnerabilities were found in Canonical's LXD today only

Six critical vulnerabilities (CVSS 9.9) were discovered in Canonical's LXD container/hypervisor tool. The flaws could allow arbitrary code execution and privilege escalation. Patches have been released; users are urged to update immediately.

Background

Six critical vulnerabilities (CVSS 9.9) were disclosed in LXD, the system container and virtual machine manager developed by Canonical (the company behind Ubuntu Linux). LXD is widely used for running lightweight, OS-level containers (not Docker-style app containers) and VMs, especially in cloud and server environments. The flaws affect all LXD versions prior to 5.21.6 (LTS) and 6.1.2. Little detail is public yet, but the severity rating (9.9 out of 10) indicates they may allow complete system compromise (e.g., escaping containers to access the host OS). Canonical has released patched versions; users should update urgently. This follows LXD's transition to a community-maintained project under the Linux Containers umbrella after Canonical stepped back from active development.