CVE-2026-34177Disclosure(canonical / lxd)

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch canonical lxd systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limits/permissions.go), which omits raw.apparmor and raw.qemu.conf from the set of keys blocked under the restricted.virtual-machines.lowlevel=block project restriction. A remote attacker with can_edit permission on a VM instance in a restricted project can inject an AppArmor rule and a QEMU chardev configuration that bridges the LXD Unix socket into the guest VM, enabling privilege escalation to LXD cluster administrator and subsequently to host root.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-184

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • lxd

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 7 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 4 mentions (2026-04-09); latest day: 2
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
lxd

Deep dive

Activity timeline8 mentions / 4d
01234Mentions · 2026-04-09: 4Mentions · 2026-04-10: 1Mentions · 2026-04-12: 1Mentions · 2026-04-13: 2Patch / Workaround · 2026-04-12: 1Patch / Workaround · 2026-04-13: 2Technical Details · 2026-04-09: 4Technical Details · 2026-04-12: 1Technical Details · 2026-04-13: 204-0904-1004-1204-13
Signal classification2 categories
Disclosure
787.5%
General
112.5%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-04-094
Disclosure4
2026-04-101
General1
2026-04-121
Disclosure1
2026-04-132
Disclosure2
Full discourse8 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: Multiple critical vulnerabilities in #Canonical #LXD e.g. #CVE-2026-34177 CVSS 9.1 These vulnerabilities allow an authenticated remote attacker to elevate their privileges to cluster admin and host root. More info https://ccb.belgium.be/advisories/warning-multiple-vulnerabilities-canonical-lxd-allowing-privilege-escalation-and-host #Patch #Patch #Patch

    Post summary

    Several critical privilege‑escalation vulnerabilities have been disclosed for Canonical LXD, including CVE-2026-34177 (CVSS 9.1), with patches referenced via the advisory link.

    01011241
    7.2K followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: Three critical bugs CVE-2026-34177, CVE-2026-34178, CVE-2026-34179 in Canonical LXD 4.12-6.7 let authenticated users escalate to cluster admin and host root, fixed in 6.8. https://threatcluster.io/cluster/critical-privilege-escalation-vulnerabilities-in-canonical-l-66d99654

    Post summary

    The text announces the discovery of three critical privilege‑escalation bugs in Canonical LXD, explains their impact and notes that a patch is available in version 6.8.

    0000047
    149 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical restriction bypass (CVE-2026-34177) affects `LXD` VM environments via `raw.apparmor` and `raw.qemu.conf`. Potential host compromise from within a VM. Restrict config access. #LXD #Virtualization #InfoSec https://www.pulsepatch.io/posts/cve-2026-34177-lxd-vm-restriction-bypass

    Post summary

    CVE-2026-34177 is a critical LXD VM restriction bypass that could allow host compromise via raw.apparmor and raw.qemu.conf, with mitigation recommended by restricting configuration access.

    0000040
    13 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-34177 📊 Severity: 9.1 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-34177 #CVE-2026-34177 #CVE #Critical #CyberSecurity #InfoSec https://t.co/v1jotlHUy9

    Post summary

    The tweet announces CVE‑2026‑34177 as a critical vulnerability with a severity score of 9.1, but it provides no technical details, exploitation evidence, or remediation guidance.

    0000023
    123 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-34177: VM lowlevel restriction bypass v... Denylist bypass lets restricted VM users inject AppArmor rules + QEMU configs to bridge LXD socket into guest, escalati... https://zerodaysignal.com/vulnerability/CVE-2026-34177 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post describes a denial‑list bypass that enables restricted VM users to inject AppArmor and QEMU configuration changes, potentially bridging the LXD socket for privilege escalation, and links to a zero‑day signal entry.

    0000068
    204 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-34177: CRITICAL] Critical #cybersecurity flaw discovered in LXD versions 4.12-6.7: incomplete denylist in isVMLowLevelOptionForbidden allows for privilege escalation by injecting malicious rules.#cve,CVE-2026-34177,#cybersecurity https://cvefind.com/CVE-2026-34177

    Post summary

    A critical privilege‑escalation flaw (CVE-2026-34177) has been disclosed in LXD 4.12‑6.7, where an incomplete denylist in isVMLowLevelOptionForbidden permits injection of malicious rules.

    0000044
    619 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-34177 Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limits/permissions.go), which omits raw.apparmor an… https://www.cve.org/CVERecord?id=CVE-2026-34177 ----- Traducción: CVE-2026-34177 Can… http://infoflow.cloud`

    Post summary

    The note announces a vulnerability (CVE‑2026‑34177) in Canonical LXD 4.12‑6.7, detailing an incomplete denylist that omits raw.apparmor, with a link to the official CVE record.

    0000034
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34177 Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limits/permissions.go), which omits raw.apparmor an… https://www.cve.org/CVERecord?id=CVE-2026-34177

    Post summary

    The passage announces CVE‑2026‑34177, highlighting a missing denylist entry in Canonical LXD's permissions logic, but does not provide any PoC, exploit, or patch information.

    00000178
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcanonicallxd---

Explore more