{"id":"GO-2025-4121","summary":"LXD vulnerable to a local privilege escalation through custom storage volumes in lxd in github.com/canonical/lxd","details":"LXD vulnerable to a local privilege escalation through custom storage volumes in lxd in github.com/canonical/lxd","aliases":["GHSA-3g2j-vm47-x4mj"],"modified":"2025-11-18T16:14:17.916056Z","published":"2025-11-18T15:44:15Z","database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2025-4121"},"references":[{"type":"ADVISORY","url":"https://github.com/canonical/lxd/security/advisories/GHSA-3g2j-vm47-x4mj"},{"type":"FIX","url":"https://github.com/canonical/lxd/pull/16904"},{"type":"FIX","url":"https://github.com/canonical/lxd/pull/16922"},{"type":"FIX","url":"https://github.com/canonical/lxd/pull/16923"},{"type":"FIX","url":"https://github.com/canonical/lxd/pull/16924"},{"type":"WEB","url":"https://github.com/lxc/incus/issues/2641"},{"type":"WEB","url":"https://github.com/lxc/incus/security/advisories/GHSA-56mx-8g9f-5crf"}],"affected":[{"package":{"name":"github.com/canonical/lxd","ecosystem":"Go","purl":"pkg:golang/github.com/canonical/lxd"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"ecosystem_specific":{"custom_ranges":[{"events":[{"introduced":"0"},{"fixed":"6.6"},{"fixed":"5.21.5"},{"fixed":"4.0.11"}],"type":"ECOSYSTEM"}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2025-4121.json"}}],"schema_version":"1.7.3"}