天下漏洞,尽知其名
CRITICAL 重点关注

CVE-2026-85185 Canonical LXD btrfs 存储驱动路径遍历漏洞

影响认证客户端可删除主机任意文件,btrfs 根文件系统下可完全控制主机

AI 研判

Canonical LXD 的 btrfs 存储驱动存在路径穿越漏洞。拥有项目内创建实例权限的认证客户端可通过构造含 ../ 序列的 subvolume 路径,以 root 身份删除主机任意文件;若主机根文件系统为 btrfs,还可写入任意内容,导致主机完全失陷。

影响范围

Canonical LXD

影响 Canonical LXD 4.0.2 及之后版本,官方已在 4.0.14、5.0.10、5.21.8 和 6.10 中修复。

漏洞详情

漏洞类型为路径穿越。成因是 btrfs 存储驱动未对 subvolume 路径中的 ../ 序列做充分校验,攻击者可将其放入优化 btrfs 备份的 optimized_header.yaml,或恶意迁移源发送的 btrfs 迁移头中。利用后以 root 权限操作主机文件系统,实现任意文件删除或写入。

利用条件与风险

利用前提是攻击者已通过认证并拥有在项目中创建实例的权限,且目标使用 btrfs 存储驱动。实战中可造成主机文件被删除,btrfs 根文件系统场景下可进一步完全接管主机,风险极高。

修复建议

官方修复方案为升级至 4.0.14、5.0.10、5.21.8 或 6.10 及以上版本。临时缓解措施暂无公开信息,建议限制可创建实例的客户端权限并避免使用 btrfs 存储驱动。

原始情报

Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete arbitrary files on the host as root. On hosts whose root filesystem is btrfs, the client can also place attacker-controlled content at arbitrary host paths, leading to full host compromise. The client does this with a crafted subvolume path containing ../ sequences, sent in either of two ways: in the optimized_header.yaml of an optimized btrfs backup, or in the btrfs migration header sent by a malicious migration source.