An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline characters within the 'nvidia.driver.capabilities' or 'nvidia.require.*' configuration values, an attacker can manipulate the generated lxc.conf file. This flaw enables the attacker to execute arbitrary code on the host system with the privileges of the LXD daemon.
Advisories
No advisories yet.
Fixes
Solution
Upgrade to LXD version 4.0.12 or later, 5.0.8 or later, or 5.12.6 or later.
Workaround
No workaround given by the vendor.
References
History
Wed, 12 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canonical
Canonical lxd |
|
| Vendors & Products |
Canonical
Canonical lxd |
Wed, 12 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline characters within the 'nvidia.driver.capabilities' or 'nvidia.require.*' configuration values, an attacker can manipulate the generated lxc.conf file. This flaw enables the attacker to execute arbitrary code on the host system with the privileges of the LXD daemon. | |
| Title | LXD arbitrary lxc.conf directive injection via NVIDIA instance configuration | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2026-08-12T19:22:07.286Z
Reserved: 2026-07-16T09:49:29.911Z
Link: CVE-2026-63298
No data.
Status : Received
Published: 2026-08-12T20:17:47.713
Modified: 2026-08-12T20:17:47.713
Link: CVE-2026-63298
No data.
OpenCVE Enrichment
Updated: 2026-08-12T23:00:05Z
Weaknesses