Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability has been identified in Canonical LXD, a system used for managing Linux containers and virtual machines. The flaw could allow an authenticated user or a malicious migration source to gain complete control of the host system by writing files to arbitrary locations. This could lead to a full compromise of the host.
- An attacker can gain full host control.
- It impacts systems managing Linux containers.
- Confirm relevance and exposure within your LXD environments.
Attack Path
How an attacker could exploit the issue
An attacker with existing access to create LXD instances or storage within a project, or by controlling a migration source, can leverage an improper link resolution flaw during data migration. By sending a specially crafted data stream, the attacker can trick the system into writing malicious files to any location on the host system with root privileges, potentially leading to complete system takeover.
- Requires authenticated client or migration source.
- Triggered by crafted migration data stream.
- Risk of full host compromise.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow an authenticated user or a malicious migration source to write arbitrary files to the host system as root. This could occur when migrating instances or custom storage volumes, using specially crafted rsync or btrfs send streams to plant and write through a symbolic link.
- Arbitrary file write on host system.
- Crafted rsync/btrfs streams during migration.
- Potential for full host compromise.
Operational Fix
Recommended remediation, mitigation, and detection steps
In real-world scenarios, platform and infrastructure teams responsible for Canonical LXD deployments should lead the remediation efforts. The immediate first step involves identifying all LXD instances, assessing their network reachability and business criticality, and pinpointing the accountable owner for each. Subsequent planning for remediation should be risk-based.
- Platform/Infrastructure teams own the issue.
- Verify LXD instance reachability and criticality.
- Plan remediation based on identified risk.