CVE-2024-6156

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
06/12/2024
Last modified:
26/08/2025

Description

Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:* 4.0.0 (including) 4.0.10 (excluding)
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:* 5.0.0 (including) 5.0.4 (excluding)
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:* 5.1 (including) 5.21.2 (excluding)