CVE-2026-9639EPSS p34.8%
CVE-2026-9639CVE-2026-9639
canonical / lxd
Description
Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted custom-volume backup tarball that omits the expires_at snapshot field.
Scoring
| CVSS | 6.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
| EPSS | 0.42% probability of exploitation · percentile 34.8% · 2026-08-11T12:00:17Z |
| Last modified | 2026-07-02 |