|
|
Subscribe / Log in / New account

Debian alert DSA-6057-1 (lxd)

From:  Salvatore Bonaccorso <carnil@debian.org>
To:  debian-security-announce@lists.debian.org
Subject:  [SECURITY] [DSA 6057-1] lxd security update
Date:  Thu, 13 Nov 2025 19:52:48 +0000
Message-ID:  <E1vJdNA-004Jgc-1F@seger.debian.org>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6057-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso November 13, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : lxd CVE ID : CVE-2025-64507 It was discovered that LXD, a system container and virtual machine manager, is prone to a local privilege escalation vulnerability if unprivileged users are allowed to access LXD through lxd-user. For the oldstable distribution (bookworm), this problem has been fixed in version 5.0.2-5+deb12u2. We recommend that you upgrade your lxd packages. For the detailed security status of lxd please refer to its security tracker page at: https://security-tracker.debian.org/tracker/lxd Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQKSBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmkWNsdfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0RJLA/4vfNSdO855hZnyW5d0scQ2TMEqbYhj4UHw+2oZDW9tx0Mw/TKS4vI1xoR vsnVWf6nZfnp+SsOHVZ0SvUR8eX50iYHfB+pAdFfc8FF6ka1kI1DU7tAg9aNbBRw x4mrzrkhBrlDTQ7073YV8eGPUCJtOJi6pTlqk70hZ/OQQMI98YoTIFDn9pJ1f6Hr XwGmA7gdjm6q9ALYB+WFReKIy/OPf9F3tpz19WuD2jBv7uD13fHV2PMz5nTlsxt0 /eeHahowAMmRPyYTNULWpiKleQY4uEoSP+KsK7N2AmknvMlBiDkGU1KL8Aeb++ku 8IcL6Cn74aCelpQXLxyrns0uT5DD18JRg/PSRPdpw3gtVHS6Eh65fo7qaOGT1T4b XeTdbm8A/S0DWmrF1S3qwHCkf2UMqZ7kWJwprx7B/9KlE+dKhs3gtim6VP6d442D +ndz47KxCy41aTH+lCuDKE5RoBaFB2e+51kI5OiEd6fy+qQpYxfAQpUbOG1NSU11 ia31S/k7bgte/8SBsGERWhIqigXE0qw7N4sPRc98oLyOMCGm+YPS17cH6ZyfZKUS 0ZYVmMsMxKnuTc0sN2iB1GEn8+U1bs58jv8nCUwWBJrlIXEBmwXAHZgjdhIQnnEM LUzWEyQSHbLr+lDkYyVWbVUDlyONa23Pp5tFAWScsW58BkI3Gg== =q+OB -----END PGP SIGNATURE-----


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds