🟠 CVE-2026-9640

CVSS 评分: 7.2(高危) | 状态: Received | 发布时间: 2026-06-26


漏洞描述

A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies during snapshot restoration.. An authenticated project operator in a restricted multi-tenant environment can bypass policy restrictions by importing a maliciously crafted instance backup containing restricted configuration keys within a snapshot. When the snapshot is restored, these restricted keys are applied to the live instance without policy validation. Starting the modified instance grants the operator unauthorized host root access.


漏洞详情

字段
CVE ID CVE-2026-9640
CVSS 评分 7.2(高危)
CVSS 向量 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE CWE-863
发布时间 2026-06-26
最后更新 2026-06-26
状态 Received
数据来源 security@ubuntu.com

参考链接


🤖 本文由 CVE 安全快讯机器人自动生成
数据来源: NVD (National Vulnerability Database) | 获取时间: 2026-06-27 03:07