Junglewise Threat Intelligence

CVE-2026-16033: LXD path traversal in QEMU template processing

CVE-2026-16033 · Severity: high · CVSS 8.5 · Published 2026-08-12

Technologies: Canonical LXD. Vendors: Canonical.

Executive brief

LXD is a container and virtual machine management system. A path traversal flaw in the QEMU/VM driver allows authenticated users who can create or restore VMs to read arbitrary files from the host (including sensitive files like /etc/shadow) and create root-owned files anywhere on the host filesystem. This could lead to exposure of confidential system data or privilege escalation.

Technical details

A path traversal vulnerability (CWE-22) exists in LXD's QEMU/VM driver template processing (driver_qemu.go, templateApplyNow function). Unlike the LXC container driver which was patched for CVE-2026-48752 with proper path validation, the QEMU driver lacks safeguards when processing template file paths from image metadata. An authenticated attacker who can create or launch a VM from a custom image or restore a VM backup can craft malicious metadata.yaml containing path traversal sequences (e.g., "../../../../etc/shadow") to read arbitrary host files or write root-owned files with a .out suffix. The vulnerability requires authentication and the ability to provide a custom image, but no user interaction is needed once the VM is launched. Patches are available in versions 4.0.12 and 5.0.7 and later.

Affected products

  • Canonical LXD 4.0.0 through 5.0.7

Timeline

  • 2026-07-31: disclosed
  • 2026-08-12: advisory
  • 2026-07-31: patched: Fixed in LXD 4.0.12 and 5.0.7+

References

Related threats