CVE-2025-54293

NameCVE-2025-54293
DescriptionPath Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attackers to read arbitrary files on the host system via crafted log file names or symbolic links.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-6027-1, DSA-6028-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
incus (PTS)trixie (security), trixie6.0.4-2+deb13u7fixed
forky, sid7.0.0-1fixed
lxd (PTS)bookworm, bookworm (security)5.0.2-5+deb12u6fixed
trixie (security), trixie5.0.2+git20231211.1364ae4-9+deb13u6fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
incussourcetrixie6.0.4-2+deb13u1DSA-6027-1
incussource(unstable)6.0.5-1
lxdsourcebookworm5.0.2-5+deb12u1DSA-6028-1
lxdsourcetrixie5.0.2+git20231211.1364ae4-9+deb13u1DSA-6028-1
lxdsource(unstable)(unfixed)

Notes

https://github.com/canonical/lxd/security/advisories/GHSA-472f-vmf2-pr3h

Search for package or bug name: Reporting problems