天下漏洞,尽知其名
CRITICAL 重点关注

CVE-2026-87799 Canonical LXD 链接解析不当漏洞

影响攻击者可以 root 权限向宿主机任意路径写入文件,完全控制宿主机

AI 研判

Canonical LXD 迁移接收路径存在链接解析不当问题,攻击者可通过构造的 rsync 或 btrfs send 数据流在传输卷中植入符号链接,进而以 root 身份向目标宿主机任意路径写入文件。该漏洞影响 LXD 4.0 及之后版本,CVSS 评分 9.9,属于严重级别。

影响范围

Canonical LXD

Canonical LXD 4.0 及之后版本,已在 4.0.14、5.0.10、5.21.8 和 6.10 中修复。

漏洞详情

漏洞类型为链接解析不当(路径穿越/符号链接攻击)。在 LXD 迁移接收流程中,程序未正确校验传输卷内的符号链接,攻击者可在 rootfs 或 root.img 等卷中植入指向宿主机任意路径的符号链接,随后通过该链接写入攻击者控制的文件。利用方式包括:具备项目内创建实例或自定义存储卷权限的已认证客户端,或恶意的迁移源服务器,发送特制的 rsync 或 btrfs send 数据流。

利用条件与风险

利用需要攻击者拥有 LXD 项目内创建实例或自定义存储卷的认证权限,或能控制迁移源服务器。成功利用后可以 root 权限写入宿主机任意文件,导致宿主机完全失陷,实战风险极高。

修复建议

官方已在 4.0.14、5.0.10、5.21.8 和 6.10 版本中修复,建议尽快升级到对应修复版本。临时缓解措施暂无公开信息,可考虑限制不受信任用户创建实例或存储卷的权限,并避免从不可信来源接收迁移。

原始情报

Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes in a project, or a malicious migration source server, to write attacker-controlled files to arbitrary paths on the target host as root, leading to full host compromise. The attacker does this with a crafted rsync or btrfs send stream that plants a symlink in the transferred volume, such as rootfs or root.img, and then writes through it.