CVE-2023-5536: Canonical Ubuntu Linux

Medium severity, CVSS 6.4. EPSS: 0.2% chance of exploitation in the next 30 days.

A feature in LXD (LP#1829071), affects the default configuration of Ubuntu Server which allows privileged users in the lxd group to escalate their privilege to root without requiring a sudo password.

Affected products

  • Canonical Ubuntu Linux: before 24.04 (fixed in 24.04)

Published 2023-12-12. Last modified 2026-06-17.