CVE-2024-6156: Canonical Lxd

Low severity, CVSS 3.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.

Affected products

  • Canonical Lxd: from 4.0.0, before 4.0.10 (fixed in 4.0.10); from 5.0.0, before 5.0.4 (fixed in 5.0.4); from 5.1, before 5.21.2 (fixed in 5.21.2)

Published 2024-12-06. Last modified 2026-06-17.