Horizon Alert
Summary of the vulnerability and why it matters
This vulnerability affects Canonical LXD on Linux, specifically its Btrfs storage driver. It allows an authenticated user with certain privileges to potentially delete or replace important files on the host system. The main concern is confirming if your environment, particularly systems managed by LXD with Btrfs backups, is exposed.
- Allows privileged users to manipulate host files.
- Matters due to potential unauthorized host system access.
- Confirm relevance and exposure; then assess remediation.
Attack Path
How an attacker could exploit the issue
An attacker with the ability to create LXD instances can abuse a path traversal flaw in the Btrfs storage driver. By providing a specially crafted entry within a backup file, an authenticated user can trick the system into deleting or overwriting critical files and directories on the host operating system with root-level privileges.
- Authenticated user with instance creation privileges.
- Crafted backup import manipulating subvolumes.
- Arbitrary file overwrite/deletion on host.
Live Threat
Current exploitation, exposure, and threat context
An authenticated user with instance creation privileges in Canonical LXD on Linux could exploit this vulnerability to delete or replace arbitrary files and directories on the host system with root privileges. This is possible by providing a specially crafted `subvolumes[].path` entry within a `backup/optimized_header.yaml` file during a btrfs optimized backup import.
- Host filesystem files and directories.
- Via crafted backup import during import.
- Arbitrary file deletion or replacement.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability affects Canonical LXD and allows authenticated users with instance creation privileges to delete or replace arbitrary files on the host filesystem. Responsibility for triage and remediation likely falls to the platform or infrastructure team managing LXD, in coordination with security and system owners. The immediate first step is to identify all LXD instances, confirm their exposure and criticality, and then plan remediation based on risk.
- Platform or infrastructure team owns issue.
- Verify LXD instance reachability and criticality.
- Plan remediation based on identified risks.