Information Spoofing in devLXD Server in Canonical LXD versions 4.0 and above on Linux container platforms allows attackers with root privileges within any container to impersonate other containers and obtain their metadata, configuration, and device information via spoofed process names in the command line.
Metrics
Affected Vendors & Products
References
History
Fri, 03 Oct 2025 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Canonical
Canonical lxd Linux Linux linux |
|
Vendors & Products |
Canonical
Canonical lxd Linux Linux linux |
Thu, 02 Oct 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 02 Oct 2025 09:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Information Spoofing in devLXD Server in Canonical LXD versions 4.0 and above on Linux container platforms allows attackers with root privileges within any container to impersonate other containers and obtain their metadata, configuration, and device information via spoofed process names in the command line. | |
Title | Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server | |
Weaknesses | CWE-290 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: canonical
Published: 2025-10-02T09:20:33.135Z
Updated: 2025-10-02T13:22:55.575Z
Reserved: 2025-07-18T07:59:07.917Z
Link: CVE-2025-54288

Updated: 2025-10-02T13:22:45.355Z

Status : Awaiting Analysis
Published: 2025-10-02T10:15:38.887
Modified: 2025-10-02T19:11:46.753
Link: CVE-2025-54288

No data.