Improper Validation of Consistency within Input Affecting github.com/canonical/lxd/lxd package, versions <6.8


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.42% (34th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMCANONICALLXDLXD-16000749
  • published13 Apr 2026
  • disclosed10 Apr 2026
  • creditmpurg

Introduced: 10 Apr 2026

CVE-2026-34178  (opens in a new tab)
CWE-1288  (opens in a new tab)

How to fix?

Upgrade github.com/canonical/lxd/lxd to version 6.8 or higher.

Overview

Affected versions of this package are vulnerable to Improper Validation of Consistency within Input through the internalImportFromBackup process in lxd/api_internal.go. An attacker can create a backup archive with a benign backup/index.yaml and a malicious backup/container/backup.yaml, then import it into a restricted project to get an instance created with security.privileged=true, raw.lxc overrides, or restricted device attachments. The imported instance is built from the unchecked backup configuration, letting a tenant with instance-creation rights in a restricted project start a container that can mount host resources and gain full LXD administrative control.

CVSS Base Scores

version 4.0
version 3.1