{"id":"GO-2026-5368","summary":"VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf in github.com/canonical/lxd","details":"VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf in github.com/canonical/lxd","aliases":["CVE-2026-34177","GHSA-fm2x-c5qw-4h6f"],"modified":"2026-08-11T23:45:11.046246598Z","published":"2026-08-11T23:21:27Z","database_specific":{"url":"https://pkg.go.dev/vuln/GO-2026-5368","review_status":"REVIEWED"},"references":[{"type":"ADVISORY","url":"https://github.com/canonical/lxd/security/advisories/GHSA-fm2x-c5qw-4h6f"},{"type":"FIX","url":"https://github.com/canonical/lxd/pull/17909"}],"affected":[{"package":{"name":"github.com/canonical/lxd","ecosystem":"Go","purl":"pkg:golang/github.com/canonical/lxd"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.0.0-20210305023314-538ac3df036e"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/canonical/lxd/lxd/project/limits","symbols":["CheckLimits"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-5368.json"}}],"schema_version":"1.9.0"}