CVE-2026-87799 in LXD: rsync and btrfs receive exposed, optimized ZFS not affected
CVE-2026-87799 in LXD lets a malicious migration stream plant a symlink and write files outside the destination volume with host privileges. rsync and btrfs receive paths are affected, while optimized ZFS transfers are not; btrfs hosts also face CVE-2026-85185 and CVE-2026-85526. Fixes ship in LXD 4.0.14, 5.0.10, 5.21.8, 6.10 and the 6.9 build at commit bf243da.
- CVE-2026-87799: symlink in migration stream writes outside volume as host
- Optimized ZFS transfers unaffected; rsync and btrfs receive affected
- btrfs hosts also carry CVE-2026-85185 and CVE-2026-85526
- ZoomEye matches 12,153 LXD assets, but storage driver is not visible
Read next
Security