Debian Package Tracker
Register | Log in
Subscribe

lxd

Choose email to subscribe with

general
  • source: lxd (main)
  • version: 5.0.2+git20231211.1364ae4-9+deb13u7
  • maintainer: Debian Go Packaging Team (DMD)
  • uploaders: Mathias Gibbens [DMD]
  • arch: all any
  • std-ver: 4.7.2
  • VCS: Git (Browse)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • oldstable: 5.0.2-5+deb12u6
  • old-sec: 5.0.2-5+deb12u6
  • stable: 5.0.2+git20231211.1364ae4-9+deb13u6
  • stable-sec: 5.0.2+git20231211.1364ae4-9+deb13u7
versioned links
  • 5.0.2-5+deb12u6: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.0.2+git20231211.1364ae4-9+deb13u6: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.0.2+git20231211.1364ae4-9+deb13u7: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • golang-github-canonical-lxd-dev
  • lxd
  • lxd-agent
  • lxd-client
  • lxd-migrate
  • lxd-tools
package is gone
This package is not in any development repository. This probably means that the package has been removed (or has been renamed). Thus the information here is of little interest ... the package is going to disappear unless someone takes it over and reintroduces it.
action needed
Debci reports failed tests high
  • unstable: fail (log)
    The tests ran in 0:00:22
    Last run: 2025-08-27T01:32:05.000Z
    Previous status: unknown

  • testing: pass (log)
    The tests ran in 0:03:03
    Last run: 2025-08-01T01:31:38.000Z
    Previous status: unknown

  • stable: pass (log)
    The tests ran in 0:03:54
    Last run: 2026-06-20T11:28:52.000Z
    Previous status: unknown

Created: 2025-08-27 Last update: 2026-06-29 01:00
5 security issues in trixie high

There are 5 open security issues in trixie.

1 important issue:
  • CVE-2026-28385: In Canonical LXD versions 4.12 through 6.9, a Server-Side Request Forgery (SSRF) vulnerability in the image import functionality allows authenticated users with the can_create_images entitlement to interact with internal network infrastructure via the /images endpoint. When importing an image from a URL source, the LXD daemon fails to validate or restrict outbound destination IP addresses, allowing connections to loopback, RFC1918 private ranges, and cloud metadata endpoints. This enables error-based port scanning and unauthorized interaction with internal HTTP services from the daemon's network position.
4 ignored issues:
  • CVE-2024-6156: Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.
  • CVE-2025-54289: Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read permissions to hijack terminal or console sessions and execute arbitrary commands via WebSocket connection hijacking format
  • CVE-2025-54290: Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence without authentication via crafted requests using wildcard fingerprints.
  • CVE-2025-54291: Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remote attackers to determine project existence via differing HTTP status code responses.
Created: 2025-08-09 Last update: 2026-06-28 17:01
15 security issues in bookworm high

There are 15 open security issues in bookworm.

11 important issues:
  • CVE-2026-9639: Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted custom-volume backup tarball that omits the expires_at snapshot field.
  • CVE-2026-9640: A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies during snapshot restoration.. An authenticated project operator in a restricted multi-tenant environment can bypass policy restrictions by importing a maliciously crafted instance backup containing restricted configuration keys within a snapshot. When the snapshot is restored, these restricted keys are applied to the live instance without policy validation. Starting the modified instance grants the operator unauthorized host root access.
  • CVE-2026-28385: In Canonical LXD versions 4.12 through 6.9, a Server-Side Request Forgery (SSRF) vulnerability in the image import functionality allows authenticated users with the can_create_images entitlement to interact with internal network infrastructure via the /images endpoint. When importing an image from a URL source, the LXD daemon fails to validate or restrict outbound destination IP addresses, allowing connections to loopback, RFC1918 private ranges, and cloud metadata endpoints. This enables error-based port scanning and unauthorized interaction with internal HTTP services from the daemon's network position.
  • CVE-2026-48749:
  • CVE-2026-48750:
  • CVE-2026-48751:
  • CVE-2026-48752:
  • CVE-2026-48755:
  • CVE-2026-48769:
  • CVE-2026-55621:
  • CVE-2026-55622:
4 ignored issues:
  • CVE-2024-6156: Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.
  • CVE-2025-54289: Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read permissions to hijack terminal or console sessions and execute arbitrary commands via WebSocket connection hijacking format
  • CVE-2025-54290: Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence without authentication via crafted requests using wildcard fingerprints.
  • CVE-2025-54291: Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remote attackers to determine project existence via differing HTTP status code responses.
Created: 2024-12-06 Last update: 2026-06-28 17:01
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2024-6156: Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.
Created: 2025-08-09 Last update: 2025-08-13 17:04
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2024-6156: Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.
Created: 2024-12-06 Last update: 2025-08-10 06:32
news
[rss feed]
  • [2026-06-28] Accepted lxd 5.0.2+git20231211.1364ae4-9+deb13u7 (source) into stable-security (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2026-05-04] Accepted lxd 5.0.2+git20231211.1364ae4-9+deb13u6 (source) into proposed-updates (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2026-05-04] Accepted lxd 5.0.2-5+deb12u6 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2026-05-04] Accepted lxd 5.0.2+git20231211.1364ae4-9+deb13u6 (source) into stable-security (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2026-05-04] Accepted lxd 5.0.2-5+deb12u6 (source) into oldstable-security (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2026-04-18] Accepted lxd 5.0.2-5+deb12u5 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2026-04-18] Accepted lxd 5.0.2+git20231211.1364ae4-9+deb13u5 (source) into proposed-updates (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2026-04-15] Accepted lxd 5.0.2+git20231211.1364ae4-9+deb13u5 (source) into stable-security (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2026-04-15] Accepted lxd 5.0.2-5+deb12u5 (source) into oldstable-security (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2026-04-02] Accepted lxd 5.0.2+git20231211.1364ae4-9+deb13u4 (source) into proposed-updates (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2026-04-02] Accepted lxd 5.0.2-5+deb12u4 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2026-03-31] Accepted lxd 5.0.2+git20231211.1364ae4-9+deb13u4 (source) into stable-security (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2026-03-31] Accepted lxd 5.0.2-5+deb12u4 (source) into oldstable-security (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2026-03-13] Accepted lxd 5.0.2-5+deb12u3 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2026-03-01] Accepted lxd 5.0.2+git20231211.1364ae4-9+deb13u3 (source) into proposed-updates (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2026-03-01] Accepted lxd 5.0.2+git20231211.1364ae4-9+deb13u3 (source) into stable-security (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2026-03-01] Accepted lxd 5.0.2-5+deb12u3 (source) into oldstable-security (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2025-12-07] Accepted lxd 5.0.2+git20231211.1364ae4-9+deb13u2 (source) into proposed-updates (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2025-11-14] Accepted lxd 5.0.2-5+deb12u2 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2025-11-13] Accepted lxd 5.0.2-5+deb12u2 (source) into oldstable-security (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2025-10-19] Accepted lxd 5.0.2-5+deb12u1 (source amd64) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2025-10-19] Accepted lxd 5.0.2+git20231211.1364ae4-9+deb13u1 (source all amd64) into proposed-updates (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2025-10-17] Accepted lxd 5.0.2-5+deb12u1 (source amd64) into oldstable-security (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2025-10-17] Accepted lxd 5.0.2+git20231211.1364ae4-9+deb13u1 (source all amd64) into stable-security (Debian FTP Masters) (signed by: Mathias Gibbens)
  • [2025-08-14] lxd REMOVED from testing (Debian testing watch)
  • [2025-05-08] lxd 5.0.2+git20231211.1364ae4-9 MIGRATED to testing (Debian testing watch)
  • [2025-04-27] Accepted lxd 5.0.2+git20231211.1364ae4-9 (source) into unstable (Mathias Gibbens)
  • [2025-03-01] lxd 5.0.2+git20231211.1364ae4-8 MIGRATED to testing (Debian testing watch)
  • [2025-02-23] Accepted lxd 5.0.2+git20231211.1364ae4-8 (source) into unstable (Mathias Gibbens)
  • [2024-08-20] lxd 5.0.2+git20231211.1364ae4-7 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • buildd: logs, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debci

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing