Skip to content
CVSS 9.9 · CRITICAL

CVE-2026-63298RCE en el host mediante inyección de configuración en LXD

An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline characters within the 'nvidia.driver.capabilities' or 'nvidia.require.*' configuration values, an attacker can manipulate the generated lxc.conf file. This flaw enables the attacker to execute arbitrary code on the host system with the privileges of the LXD daemon.

Ver en NVD

Análisis

A critical vulnerability in LXD allows users with instance configuration access to escape to the host system. By injecting newline characters in NVIDIA configuration directives, an attacker can execute arbitrary code as root on the host machine. Infrastructure teams using LXD for multi-tenant or GPU workloads should update immediately.

Roles relevantes

LinuxDockerKubernetesCloudIABackend

Severidad

Puntaje: 9.9(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: LOW
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Tipo de falla (CWE): CWE-78

EPSS

Sin puntaje EPSS aún (CVE muy reciente).

Descripción técnica

An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline characters within the 'nvidia.driver.capabilities' or 'nvidia.require.*' configuration values, an attacker can manipulate the generated lxc.conf file. This flaw enables the attacker to execute arbitrary code on the host system with the privileges of the LXD daemon.

Publicada: 12/8/2026, 20:17:47
Última modificación: 12/8/2026, 20:17:47

Referencias

InicioEventosBlogRecursosCursosEquipo