← Back to search

CVE-2026-85185

9.6 CRITICALpublic exploit available

Published 2026-09-28 · Updated 2026-09-28

AI risk analysis

Summary
This flaw allows an authenticated client to traverse paths and delete arbitrary files or inject content on the host, leading to potential full host compromise.
Exploitability
Exploitation requires authentication and permission to create instances in a project. The attacker must send a crafted subvolume path containing ../ sequences.
Blast radius
If exploited, the attacker can gain full control over the host system, leading to severe data loss or system compromise.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to LXD 4.0.14, 5.0.10, 5.21.8, or 6.10 or later.
rcepath-traversalbtrfshost-compromise

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete arbitrary files on the host as root. On hosts whose root filesystem is btrfs, the client can also place attacker-controlled content at arbitrary host paths, leading to full host compromise. The client does this with a crafted subvolume path containing ../ sequences, sent in either of two ways: in the optimized_header.yaml of an optimized btrfs backup, or in the btrfs migration header sent by a malicious migration source.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H

Weaknesses

CWE-22

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.