CVE-2026-9639: Canonical Lxd

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted custom-volume backup tarball that omits the expires_at snapshot field.

Affected products

  • Canonical Lxd: from 5.0.0, before 5.21.5 (fixed in 5.21.5); from 6.0, before 6.9 (fixed in 6.9)

Published 2026-06-26. Last modified 2026-07-02.