Security News

Cybersecurity news aggregator

🐧
HIGH Updates Debian Security

DSA-6213-1 lxd - security update

Multiple critical vulnerabilities (CVE-2026-34177, CVE-2026-34178, CVE-2026-34179, each with a CVSS 3.1 score of 9.1) in the LXD container manager could result in restriction bypass or privilege escalation. For Debian 12 (Bookworm), the issues are fixed in lxd version 5.0.2-5+deb12u5, and for Debian 13 (Trixie), in version 5.0.2+git20231211.1364ae4-9+deb13u5. Administrators should upgrade their lxd packages to these patched versions immediately.
Read Full Article →

[SECURITY] [DSA 6213-1] lxd security update To : debian-security-announce@lists.debian.org Subject : [SECURITY] [DSA 6213-1] lxd security update From : Moritz Muehlenhoff < jmm@debian.org > Date : Wed, 15 Apr 2026 19:16:46 +0000 Message-id : < [🔎] ad_kHrfI2OtoEQEs@seger.debian.org > Reply-to : debian-security-announce-request@lists.debian.org -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6213-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff April 15, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : lxd CVE ID : CVE-2026-34177 CVE-2026-34178 CVE-2026-34179 Multiple security issues were discovered in LXD, a system container and virtual machine manager, which could result in restriction bypass or privilege escalation. For the oldstable distribution (bookworm), these problems have been fixed in version 5.0.2-5+deb12u5. For the stable distribution (trixie), these problems have been fixed in version 5.0.2+git20231211.1364ae4-9+deb13u5. We recommend that you upgrade your lxd packages. For the detailed security status of lxd please refer to its security tracker page at: https://security-tracker.debian.org/tracker/lxd Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmnf4xYACgkQEMKTtsN8 Tja0jg/9HaSia3S0gnX6GwWxF9dIITxR6XpOiPC13ekScksFj0AHK6kQC7TpQKD/ TIqxgfzKxdsGho55V01X9FL5IbRAM2EvkRXaDILHeLp0H3YR45QNayOiEO0h0fhL Jy/jMmpDD0o7CGWDAPLEvqwb6ZiMd/LGdDOsFPP2FGZTFScb6PHa77jnflQTk+9G VquNQ1rCpTaFFwVIzThq7YQ5osElS9k079W7Yjzyfu/kAAxmlYVnUR+kXU0zPoLm Pj1XhTmiUE6PrctNtkkuhO70lHWY9DZhmp0EJKW9paCOKmlWbfxcWuKauTwYKLng diOaIijMvXhn6WuGbdtPrF2sYONjNsP7vCU6J4fPaLhtS0jFNlqjl7r7P78ToJOI +esUP9L1x8PpbEjLhJPKYMlsV0Bb9IJ/hz2YyaM+cGUIAEaGCGnO0WCySbo2JKSq Ena8KqkCzn5GJveNyL7DQWyiuOPYx2cdStKz2guE3VBJZeMM19VFnHCCE5wJLq94 ZKwOohwbOMb5TaFGby9y1qerIjgDFa+jVgW5Eij7igh6w88wiPrki2XIfjI/eoyN mVW7L4xw7oQlIY9JzDmxC8Q9UMAU+Agn+OF2splX2pITeCzphSp6vFKw3pgzxgKa MwL8l0mZeVTqK/CoDEaADUiaTahW9DhUBh30odA0W9l+wR4iPWU= =WvaS -----END PGP SIGNATURE----- Reply to: debian-security-announce@lists.debian.org Moritz Muehlenhoff (on-list) Moritz Muehlenhoff (off-list) Prev by Date: [SECURITY] [DSA 6212-1] incus security update Previous by thread: [SECURITY] [DSA 6212-1] incus security update Index(es): Date Thread

Share this article