Skip to content
COOEY

FAIL › dossier

lxd

PRODUCT

Dossier not yet built — the RAG curator builds one for players with ≥2 failure events. The failure history and sentiment below are live.
FAILURE HISTORY · 1
DATEEVENTSEVSUMMARY
2026-06-26 CVE-2026-12411 high Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when security.devlxd.management.volumes is enabled.