CVE-2024-6219: Canonical Lxd

Low severity, CVSS 3.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.

Affected products

  • Canonical Lxd: before 5.21.1 (fixed in 5.21.1)

Published 2024-12-06. Last modified 2026-06-17.