Path Traversal via btrfs Subvol Path in Canonical LXD 4.0.2+ (fixed 4.0.14+)
CVE-2026-85185 Published on September 28, 2026
Path traversal in LXD btrfs storage driver allows arbitrary file deletion and write on host as root
Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete arbitrary files on the host as root. On hosts whose root filesystem is btrfs, the client can also place attacker-controlled content at arbitrary host paths, leading to full host compromise. The client does this with a crafted subvolume path containing ../ sequences, sent in either of two ways: in the optimized_header.yaml of an optimized btrfs backup, or in the btrfs migration header sent by a malicious migration source.
Vulnerability Analysis
CVE-2026-85185 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. Public availability of a proof of concept (POC) exploit exists for CVE-2026-85185. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity and availability.
Weakness Type
What is a Directory traversal Vulnerability?
The software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVE-2026-85185 has been classified to as a Directory traversal vulnerability or weakness.
Products Associated with CVE-2026-85185
Want to know whenever a new CVE is published for Canonical Lxd? stack.watch will email you.
Affected Versions
Canonical LXD:- Version 4.0.2 and below 4.0.14 is affected.
- Version 5.0.0 and below 5.0.10 is affected.
- Version 5.21.0 and below 5.21.8 is affected.
- Version 6.0 and below 6.10 is affected.