External risk intelligence

Canonical LXD Path Traversal Allows Root File Deletion and Host Compromise

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-85185

The vulnerability resides in the LXD storage driver and requires an authenticated client with existing permissions to create instances. While LXD may be network-accessible, it is typically managed by authorized administrators or internal users within a controlled environment, making direct public-internet exposure of the specific vulnerable instance-creation workflow uncommon.

Path Traversal

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in the LXD storage driver could allow an authenticated client to delete arbitrary files on the host system or gain full host control, particularly on systems using the btrfs filesystem. This issue arises from a path traversal flaw that can be exploited through specially crafted subvolume paths during instance creation or backup operations.

  • Allows authenticated users to delete host files.
  • Could lead to full host compromise on btrfs systems.
  • Confirm if LXD instance creation is exposed externally.

Attack Path

How an attacker could exploit the issue

An attacker with authenticated access to a project within Canonical LXD could exploit a path traversal vulnerability in the btrfs storage driver. This allows them to delete arbitrary files on the host system as root. If the host's root filesystem is btrfs, the attacker can also write malicious content to any location on the host, leading to a full system compromise. This is achieved by manipulating subvolume paths with directory traversal sequences.

  • Authenticated client with instance creation permissions.
  • Crafted subvolume path in backup or migration data.
  • Arbitrary file deletion and host compromise.

Live Threat

Current exploitation, exposure, and threat context

An authenticated client with instance creation privileges on a Linux host using the btrfs storage driver could delete arbitrary files as root. When supported by the advisory, this could also lead to placing attacker-controlled content at arbitrary host paths and achieving full host compromise.

  • Arbitrary file deletion and host compromise.
  • Exploitation via crafted subvolume paths.
  • Full host compromise and data manipulation.

Operational Fix

Recommended remediation, mitigation, and detection steps

To address this vulnerability, the teams responsible for managing LXD instances and the underlying host infrastructure should collaborate. The first practical step involves identifying all LXD hosts, pinpointing where the affected storage driver is utilized, and determining its reachability and criticality to business operations. Subsequently, the accountable owner must be identified to coordinate remediation efforts.

  • LXD and infrastructure teams own the fix.
  • Verify LXD instance creation access.
  • Plan phased remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Canonical LXD?

Canonical LXD is a next-generation system container manager for Linux. It provides a specialized environment to manage system containers and virtual machines, allowing users to run full operating systems in isolated instances. It is widely used for infrastructure virtualization, cloud deployments, and developer environments, relying on storage drivers like btrfs to handle these instance filesystems efficiently.

What does CWE-22 mean for CVE-2026-85185?

CWE-22 is the weakness classification for improper limitation of a pathname to a restricted directory, commonly known as path traversal. In this vulnerability, it means the LXD btrfs storage driver fails to properly sanitize input. An attacker can use '..' sequences in subvolume paths to escape the intended directory, allowing them to reference and manipulate files anywhere on the host system.

How is this path traversal flaw triggered?

The vulnerability is triggered when an authenticated user sends a crafted subvolume path containing directory traversal sequences. This occurs specifically during two actions: importing an optimized btrfs backup via a specially crafted header or during a btrfs migration from a malicious source. Simply browsing or reading existing instances without performing these migration or backup-related operations does not trigger the bug.

Who is at risk according to Halo Surface Signal?

Risk is limited to environments where users have permission to create instances within an LXD project. According to Halo Surface Signal, while LXD services can be network-accessible, direct public-internet exposure of the specific instance-creation workflow is uncommon. The primary concern remains internal users or accounts with existing authorization who might abuse these administrative privileges.

What should I do to respond to this vulnerability?

Start by identifying all hosts running LXD and confirming which systems use the btrfs storage driver. Since this requires local or project-level authentication, verify who currently holds instance-creation permissions and ensure those accounts are managed securely. Coordinate with your infrastructure team to plan an update to the patched versions of LXD listed in the advisory to close the path traversal vector.

References