Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attackers to read arbitrary files on the host system via crafted log file names or symbolic links.
Metrics
Affected Vendors & Products
References
History
Wed, 10 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linux linux Kernel
|
|
| CPEs | cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Linux linux Kernel
|
|
| Metrics |
cvssV3_1
|
Fri, 03 Oct 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canonical
Canonical lxd Linux Linux linux |
|
| Vendors & Products |
Canonical
Canonical lxd Linux Linux linux |
Thu, 02 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 02 Oct 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attackers to read arbitrary files on the host system via crafted log file names or symbolic links. | |
| Title | Path Traversal in LXD Instance Log File Retrieval | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: canonical
Published: 2025-10-02T10:43:58.246Z
Updated: 2025-10-02T15:53:20.364Z
Reserved: 2025-07-18T07:59:07.917Z
Link: CVE-2025-54293
Updated: 2025-10-02T15:29:39.925Z
Status : Analyzed
Published: 2025-10-02T11:15:30.540
Modified: 2025-12-10T19:31:47.857
Link: CVE-2025-54293
No data.