Risk Scores
CVSS v4.0
9.399999618530273
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
EPSS Score
0.13%
32.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical | lxd | 6.0, 5.21.0, 5.0.0 |
Timeline
- Mar 12, 2026 CVE Published
- Mar 12, 2026 PoC Published
- Mar 13, 2026 EPSS Score
- Mar 13, 2026 CVE Updated
- Mar 14, 2026 EPSS Score
- Mar 15, 2026 EPSS Score
- Mar 16, 2026 EPSS Score
- Mar 17, 2026 EPSS Score
- Mar 17, 2026 Coalition ESS Score
- Mar 18, 2026 EPSS Score
- Mar 19, 2026 EPSS Score
- Mar 20, 2026 EPSS Score
References
- https://github.com/canonical/lxd/security/advisories/GHSA-4rmf-rcp8-2r9g vendor-advisory
- https://github.com/canonical/lxd/commit/043696a13171ace7dd4c2b32d34ce039ab629052 patch
- https://github.com/canonical/lxd/commit/7046979645c2ce1b63b2f9e60ddf6cbc4c4b78f9 patch
- https://github.com/canonical/lxd/commit/b7b411caf5c4971bfe2386c72128f44d7e2aaf4f patch
- https://discourse.ubuntu.com/t/lxd-authenticated-remote-code-execution-fixes-available/78365 url