CVE-2016-1581: Canonical Lxd

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

LXD before 2.0.2 uses world-readable permissions for /var/lib/lxd/zfs.img when setting up a loop based ZFS pool, which allows local users to copy and read data from arbitrary containers via unspecified vectors.

Affected products

  • Canonical Lxd: up to and including 2.0.1
  • Canonical Ubuntu Linux: version 15.10 only; version 16.04 only

Published 2016-06-09. Last modified 2026-06-17.