chiprook
← Security
SecurityOctober 3, 2026, 15:20

CVE-2026-87799 in LXD: rsync and btrfs receive exposed, optimized ZFS not affected

CVE-2026-87799 in LXD lets a malicious migration stream plant a symlink and write files outside the destination volume with host privileges. rsync and btrfs receive paths are affected, while optimized ZFS transfers are not; btrfs hosts also face CVE-2026-85185 and CVE-2026-85526. Fixes ship in LXD 4.0.14, 5.0.10, 5.21.8, 6.10 and the 6.9 build at commit bf243da.

CVE-2026-87799 in LXD: rsync and btrfs receive exposed, optimized ZFS not affected
#LXD#ZFS#Btrfs#Rsync
Read next
Security

LXD hit by three critical flaws rated up to 9.9

Security

MetaMask Reports Ongoing Security Incident Affecting Infrastructure

Security

CVE-2026-96357 in Drupal: 16 modules, 19 affected version ranges

Security

Times Car confirms data breach affecting 6.6 million accounts