Executive brief
LXD is a container management system used to deploy and manage virtual machines and containers across infrastructure. An authenticated user with valid credentials can exploit improper input validation to execute arbitrary commands as the LXD daemon, potentially gaining full control of the container host. This vulnerability affects LXD versions from 4.12 onwards where unprivileged users were restricted by the project feature.
Technical details
The vulnerability is a command injection flaw in the compression_algorithm parameter handling for the image and backup API endpoints. The affected code fails to properly sanitize user-supplied compression algorithm values before passing them to the backend processor, which prepends "-c" to create shell commands. An authenticated attacker can craft a payload like "bash \"sleep 1\"" that gets processed as "bash -c \"sleep 1\"", achieving arbitrary command execution as the LXD daemon. The issue exists in LXD versions 4.12 through 6.6; fixed versions include 5.0.6-e49d9f4, 5.21.4-1374f39, 6.7-1f11451, and later. No authentication bypass is required; the attacker must possess valid LXD credentials.
Affected products
- Canonical LXD 4.12 through 6.6
Timeline
- 2026-03-12: disclosed: Vulnerability CVE-2026-28384 disclosed; fixes available for snap channels 5.0, 5.21, and 6.0
- 2026-03-11: patched: Patches released: 5.0.6-e49d9f4 (5.0/stable), 5.21.4-1374f39 (5.21/stable), 6.7-1f11451 (6.0/stable)