CVE-2026-9639
MEDIUM
NVD
CVSS Score
6.5
Severity
MEDIUM
Published
Jun 26, 2026
Vendor
unknown
Description
Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted custom-volume backup tarball that omits the expires_at snapshot field.