5.1
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
Description
Information Spoofing in devLXD Server in Canonical LXD versions 4.0 and above on Linux container platforms allows attackers with root privileges within any container to impersonate other containers and obtain their metadata, configuration, and device information via spoofed process names in the command line.
Basic Information
ID
CVE-2025-54288
Source
canonical
Published
Oct 2, 2025 at 09:20
Affected Product
Vendor
Canonical
Product
LXD
Version
6.0
Affected Versions
Canonical LXD 6.0
Canonical LXD 5.21
Canonical LXD 5.21