VDB

DEBIAN-CVE-2025-54288

DEBIAN-CVE-2025-54288 PUBLISHED CVSS 6.800000190734863 MEDIUM

Information Spoofing in devLXD Server in Canonical LXD versions 4.0 and above on Linux container platforms allows attackers with root privileges within any container to impersonate other containers and obtain their metadata, configuration, and device information via spoofed process names in the command line.

Risk Scores

CVSS v3.1
6.800000190734863
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

Affected Products

VendorProductVersions
Debian:13lxd0, 5.0.2+git20231211.1364ae4-9, 0
Debian:14incus0, 0, 6.0.4-2
Debian:13incus6.0.4-2, 0, 6.0.4-2
Debian:12lxd0, 5.0.2-5, 0

Timeline

  • Oct 2, 2025 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›