PatchSiren cyber security CVE debrief
CVE-2026-9639 Canonical CVE debrief
CVE-2026-9639 is a medium-severity vulnerability in LXD, a container hypervisor, that allows an authenticated user with 'can_create_storage_volumes' permissions to cause a denial of service. The vulnerability is due to a nil-pointer dereference in the 'CreateCustomVolumeFromBackup' function. An attacker can exploit this vulnerability by providing a specially crafted custom-volume backup tarball that omits the 'expires_at' snapshot field. This vulnerability affects LXD versions up to 6.8 and 5.21 on Linux.
- Vendor
- Canonical
- Product
- Lxd
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-26
- Original CVE updated
- 2026-07-02
- Advisory published
- 2026-06-26
- Advisory updated
- 2026-07-02
Who should care
Users of LXD, particularly those with LXD versions up to 6.8 and 5.21, should be aware of this vulnerability. Authenticated users with 'can_create_storage_volumes' permissions are potentially able to exploit this vulnerability. Administrators of Linux systems using LXD should assess their exposure and take necessary mitigation steps.
Technical summary
The vulnerability is caused by a nil-pointer dereference in the 'CreateCustomVolumeFromBackup' function of LXD. This function is used to create a custom volume from a backup. The vulnerability can be exploited by an authenticated user with 'can_create_storage_volumes' permissions, who can provide a specially crafted custom-volume backup tarball that omits the 'expires_at' snapshot field, leading to a denial of service.
Defensive priority
Medium priority should be given to patching LXD versions up to 6.8 and 5.21. Administrators should ensure that only authorized users have 'can_create_storage_volumes' permissions.
Recommended defensive actions
- Patch LXD to version 6.9 or later, or 5.21.5 or later.
- Restrict 'can_create_storage_volumes' permissions to only necessary users.
- Monitor LXD logs for suspicious activity.
- Perform regular security audits of LXD configurations and user permissions.
- Consider implementing additional security controls, such as network access controls and intrusion detection systems.
Evidence notes
The CVE-2026-9639 vulnerability was made public on June 26, 2026, and last modified on July 2, 2026. The vulnerability affects LXD versions up to 6.8 and 5.21 on Linux. The CVSS score for this vulnerability is 6.5, with a severity rating of Medium.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-9639 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-9639
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-9639 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9639
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/canonical/lxd/pull/18320
[email protected] - Issue Tracking, Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/canonical/lxd/pull/18390
[email protected] - Issue Tracking, Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/canonical/lxd/security/advisories/GHSA-j93m-3j9p-m5m8
[email protected] - Exploit, Patch, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.