github.comvdb entryVendor advisory
https://github.com/canonical/lxd/security/advisories/GHSA-vfh7-q59q-54v2 CVE-2026-63298
HIGH
LXD arbitrary lxc.conf directive injection via NVIDIA instance configuration
Record summary
CVE-2026-63298 has a selected CVSS score of 8.7 (high).
Description
An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline characters within the 'nvidia.driver.capabilities' or 'nvidia.require.*' configuration values, an attacker can manipulate the generated lxc.conf file. This flaw enables the attacker to execute arbitrary code on the host system with the privileges of the LXD daemon.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 13, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | 5.0.0 to < 5.0.8 | affected |
| 5.21.0 to < 5.21.6 | affected | ||
| 4.0.0 to < 4.0.12 | affected |