Tracker / CVE-2026-9639
CVE-2026-9639
Medium 6.5
Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted custom-volume backup tarball that omits the expires_at snapshot field.
Affected products and versions
| canonical | lxd · 5.0.0 → 5.21.5 |
|---|---|
| canonical | lxd · 6.0 → 6.9 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.