CVE-2026-85526 | Canonical LXD up to 4.0.13/5.0.9/5.21.7/6.9 Btrfs storage driver optimized_header.yaml unpackVolume subvolumes[] path traversal

SecurityVulns

A vulnerability identified as very critical has been detected in Canonical LXD up to 4.0.13/5.0.9/5.21.7/6.9. This issue affects the function unpackVolume of the file backup/optimized_header.yaml of the component Btrfs storage driver. Performing a manipulation of the argument subvolumes[] results in path traversal.

This vulnerability was named CVE-2026-85526. The attack may be initiated remotely. There is no available exploit.

You should upgrade the affected component.VulDB Recent EntriesRead More