Security Advisory

CVE-2026-9639

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-26 15:39:04
Last updated 2026-06-26 16:02:11
Assigner canonical
CVSS score 6.5
State PUBLISHED

Description

Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted custom-volume backup tarball that omits the expires_at snapshot field.