CyberRota Analysis
AI-GeneratedThe btrfs storage driver in Canonical LXD versions 4.0.2 and later is vulnerable to a path traversal attack, allowing authenticated clients with instance creation permissions to delete arbitrary files on the host system as root. This vulnerability can lead to full host compromise, particularly on systems using btrfs as the root filesystem, as attackers can exploit crafted subvolume paths to manipulate file locations. Organizations using affected LXD versions should prioritize immediate updates to versions 4.0.14, 5.0.10, 5.21.8, or 6.10 to mitigate this critical risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete arbitrary files on the host as root. On hosts whose root filesystem is btrfs, the client can also place attacker-controlled content at arbitrary host paths, leading to full host compromise. The client does this with a crafted subvolume path containing ../ sequences, sent in either of two ways: in the optimized_header.yaml of an optimized btrfs backup, or in the btrfs migration header sent by a malicious migration source.