CVE-2026-9639: Canonical Lxd
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted custom-volume backup tarball that omits the expires_at snapshot field.
Affected products
- Canonical Lxd: from 5.0.0, before 5.21.5 (fixed in 5.21.5); from 6.0, before 6.9 (fixed in 6.9)
Published 2026-06-26. Last modified 2026-07-02.