Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability in the LXD storage driver could allow an authenticated client to delete arbitrary files on the host system or gain full host control, particularly on systems using the btrfs filesystem. This issue arises from a path traversal flaw that can be exploited through specially crafted subvolume paths during instance creation or backup operations.
- Allows authenticated users to delete host files.
- Could lead to full host compromise on btrfs systems.
- Confirm if LXD instance creation is exposed externally.
Attack Path
How an attacker could exploit the issue
An attacker with authenticated access to a project within Canonical LXD could exploit a path traversal vulnerability in the btrfs storage driver. This allows them to delete arbitrary files on the host system as root. If the host's root filesystem is btrfs, the attacker can also write malicious content to any location on the host, leading to a full system compromise. This is achieved by manipulating subvolume paths with directory traversal sequences.
- Authenticated client with instance creation permissions.
- Crafted subvolume path in backup or migration data.
- Arbitrary file deletion and host compromise.
Live Threat
Current exploitation, exposure, and threat context
An authenticated client with instance creation privileges on a Linux host using the btrfs storage driver could delete arbitrary files as root. When supported by the advisory, this could also lead to placing attacker-controlled content at arbitrary host paths and achieving full host compromise.
- Arbitrary file deletion and host compromise.
- Exploitation via crafted subvolume paths.
- Full host compromise and data manipulation.
Operational Fix
Recommended remediation, mitigation, and detection steps
To address this vulnerability, the teams responsible for managing LXD instances and the underlying host infrastructure should collaborate. The first practical step involves identifying all LXD hosts, pinpointing where the affected storage driver is utilized, and determining its reachability and criticality to business operations. Subsequently, the accountable owner must be identified to coordinate remediation efforts.
- LXD and infrastructure teams own the fix.
- Verify LXD instance creation access.
- Plan phased remediation based on risk.