CVE-2016-1581: Canonical Lxd
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
LXD before 2.0.2 uses world-readable permissions for /var/lib/lxd/zfs.img when setting up a loop based ZFS pool, which allows local users to copy and read data from arbitrary containers via unspecified vectors.
Affected products
- Canonical Lxd: up to and including 2.0.1
- Canonical Ubuntu Linux: version 15.10 only; version 16.04 only
Published 2016-06-09. Last modified 2026-06-17.