Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to LXD version 4.0.12 or later, 5.0.8 or later, or 5.12.6 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 12 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canonical
Canonical lxd |
|
| Vendors & Products |
Canonical
Canonical lxd |
Wed, 12 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline characters within the 'nvidia.driver.capabilities' or 'nvidia.require.*' configuration values, an attacker can manipulate the generated lxc.conf file. This flaw enables the attacker to execute arbitrary code on the host system with the privileges of the LXD daemon. | |
| Title | LXD arbitrary lxc.conf directive injection via NVIDIA instance configuration | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2026-08-12T19:22:07.286Z
Reserved: 2026-07-16T09:49:29.911Z
Link: CVE-2026-63298
No data.
Status : Received
Published: 2026-08-12T20:17:47.713
Modified: 2026-08-12T20:17:47.713
Link: CVE-2026-63298
No data.
OpenCVE Enrichment
Updated: 2026-08-12T21:00:03Z