CVE-2026-63297
PoC largeTOCTOU Authorization Bypass in Canonical LXD Cross-Project Copies
CVE-2026-63297 is an authorization bypass in Canonical's LXD container/systems manager caused by a time-of-check to time-of-use (TOCTOU) race during configuration merging. When an authenticated user copies an instance into a target project, LXD performs its restriction checks before the configuration merge finishes, allowing the attacker to slip past those checks. As a result, the attacker can copy an instance carrying disallowed high-privilege configuration (e.g., privileged settings) into a project where such configuration is supposed to be forbidden, gaining elevated capabilities within that restricted project and potentially weakening project isolation. Any LXD deployment that uses projects with restrictions and permits cross-project instance copies is affected; exploitability requires an authenticated low-privilege LXD user and no user interaction. Exploitation has not been observed in the wild (not in CISA KEV, EPSS ~0.2%), but a public advisory reference (GHSA-v989-qw7w-xvg4) exists.
What to do: Upgrade LXD to the fixed release identified in Canonical's security advisory (GHSA-v989-qw7w-xvg4), as no fixed version is listed in the data provided. Until patched, restrict which authenticated users may perform cross-project instance copies and consider temporarily disallowing copies into restricted projects, then audit restricted projects for instances containing disallowed high-privilege configuration. Minimize network exposure of the LXD API (port 8443) since the flaw is remotely exploitable by any authenticated user.
| canonical lxd | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a target project, LXD performs restriction checks before configuration merging is complete, creating a time-of-check to time-of-use (TOCTOU) condition. An attacker can exploit this flaw to copy instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.
- Vendors
- canonical
- Products
- lxd
- Weakness
- CWE-367, CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.