Vulnerabilities & Exploits
Debian Patches LXD Flaws Allowing Command Execution
Debian released security updates for LXD. Two vulnerabilities (CVE-2026-23953, CVE-2026-23954) can execute arbitrary commands via malformed images.
1 source · Mar 1
CVE-2026-23954
NVD KEV
CVSS 8.7 HIGH: incus is a system container and virtual machine manager. EPSS 0.7% (52nd percentile).
CVE-2026-23953
NVD KEV
CVSS 8.7 HIGH: incus is a system container and virtual machine manager. EPSS 0.5% (39th percentile).
Timeline
Sources
Debian Security Advisories
SECURITY] [DSA 6153-1] lxd security update
SECURITY] [DSA 6153-1] lxd security update -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - Debian Security Advisory DSA-6153-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff March 01, 2026 https://www.debian.org/security/faq - Package : lxd CVE ID…
original
Part of the PlainSec briefing for 2026-03-01
Every edition of this story: Debian Patches LXD Flaws Allowing Command Execution
More from today