Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5052 articles · 189092 vulns · 37/41 feeds (7d)
← Back to list
8.5
CVE-2026-63299PATCHED
canonical · lxd

Storage volume cross-project move and snapshot restore bypass project disk limits

Description

An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource limits during volume operations: the storagePoolVolumeTypePostMove function omits the limits.AllowVolumeCreation check before moving a volume across projects, and volume snapshot restore operations skip the AllowVolumeUpdate check when the configuration is nil (Config == nil). An attacker can exploit these flaws to allocate storage resources that exceed the administrative limits configured for a project.

Affected Products

VendorProductVersions
canonicallxd5.0.0, 5.21.0, 6.0

References

  • https://github.com/canonical/lxd/security/advisories/GHSA-5h78-p252-989h(vdb-entry, vendor-advisory)

Related News (1 articles)

Tier C
VulDB1h ago
CVE-2026-63299 | Canonical LXD up to 5.0.7/5.21.5/6.9 Volume Operations storagePoolVolumeTypePostMove authorization
→ No new info (linked only)
CVSS 3.18.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
5.0.85.21.66.10
CWECWE-770
PublishedAug 12, 2026
Trending Score27
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-63297
Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge
Trending: 42
CRITICALCVE-2026-63296
Project restriction bypass via instance migration config override
Trending: 42
HIGHCVE-2026-63298
LXD arbitrary lxc.conf directive injection via NVIDIA instance configuration
Trending: 39
MEDIUMCVE-2026-63295
Project restriction `restricted.containers.privilege=isolated` bypassable by omitting `security.idmap.isolated`
Trending: 35
CRITICALCVE-2026-63293
Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root
Trending: 30

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 12, 2026
Discovered by ZDM
Aug 12, 2026
Patch Available
Aug 12, 2026