CVE-2024-6156

LOW3.8EPSS 0.05%

CA certificate sign check bypass in github.com/canonical/lxd

Published: 12/9/2024Modified: 4/28/2026

Description

Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.

Affected packages (4)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1LOW3.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

References (7)