FlawAtlas
Search the atlas
USN-6738-1 Not scored

lxd vulnerability

Fabian Bäumer, Marcus Brinkmann, and Jörg Schwenk discovered that LXD incorrectly handled the handshake phase and the use of sequence numbers in SSH Binary Packet Protocol (BPP). If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to bypass integrity checks.

Exploit probability Not scored
Published April 22, 2024
Required by Not available
Last source change June 25, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:Pro:16.04:LTS lxd

73 explicit affected versions

Ubuntu:Pro:18.04:LTS lxd

20 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities USN-6738-1

Fabian Bäumer, Marcus Brinkmann, and Jörg Schwenk discovered that LXD incorrectly handled the handshake phase and the use of sequence numbers in SSH Binary Packet Protocol (BPP). If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to bypass integrity checks.

View original source

05 / REFERENCES

Further evidence