GHSA-x9qq-236j-gj97

    Dashboard / Vulnerabilities / GHSA-x9qq-236j-gj97

    GHSA-x9qq-236j-gj97

    Published: 5 Dec 2023Last Modified: 22 Jul 2025

    Summary: Canonical LXD documentation improvement to make clear restricted.devices.disk=allow without restricted.devices.disk.paths also allows shift=true

    Details: ### Summary If a user has restricted access to a project that is configured with `restricted=true`, they can gain root access on the system by creating a disk device with `shift=true` and creating a setuid root executable. This is possible because the `shift` property is not restricted unless `restricted.devices.disk.paths` is set. ### Details The following patch shows the offending code with a possible fix: ```patch --- a/lxd/device/disk.go +++ b/lxd/device/disk.go @@ -429,17 +429,19 @@ func (d *disk) validateEnvironmentSourcePath() error { if instProject.Name != api.ProjectDefaultName { // If restricted disk paths are in force, then check the disk's source is allowed, and record the // allowed parent path for later user during device start up sequence. - if shared.IsTrue(instProject.Config["restricted"]) && instProject.Config["restricted.devices.disk.paths"] != "" { - allowed, restrictedParentSourcePath := project.CheckRestrictedDevicesDiskPaths(instProject.Config, d.config["source"]) - if !allowed { - return fmt.Errorf("Disk source path %q not allowed by project for disk %q", d.config["source"], d.name) + if shared.IsTrue(instProject.Config["restricted"]) { + if instProject.Config["restricted.devices.disk.paths"] != "" { + allowed, restrictedParentSourcePath := project.CheckRestrictedDevicesDiskPaths(instProject.Config, d.config["source"]) + if !allowed { + return fmt.Errorf("Disk source path %q not allowed by project for disk %q", d.config["source"], d.name) + } + + d.restrictedParentSourcePath = shared.HostPath(restrictedParentSourcePath) } if shared.IsTrue(d.config["shift"]) { return fmt.Errorf(`The "shift" property cannot be used with a restricted source path`) } - - d.restrictedParentSourcePath = shared.HostPath(restrictedParentSourcePath) } } ``` ### PoC ```bash $ lxc project create restricted -c restricted=true -c restricted.devices.disk=allow $ lxc project switch restricted $ lxc profile device add default root disk path=/ pool=default $ lxc init ubuntu:22.04 c1 $ lxc config device add c1 d1 disk source=/ path=/mnt shift=true $ lxc start c1 # no error $ lxc project set restricted restricted.devices.disk.paths=/ # explicitly allow mounting / $ lxc restart c1 Error: Failed to start device "d1": The "shift" property cannot be used with a restricted source path ``` Created https://github.com/canonical/lxd/issues/12606 to improve the documentation as per https://github.com/canonical/lxd/security/advisories/GHSA-x9qq-236j-gj97#advisory-comment-91918

    Affected packages

    Package

    Name: github.com/canonical/lxd

    Purl: pkg:golang/github.com/canonical/lxd

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 5.19.0
    Fixed -5.20.0

    Affected versions

    5.19.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-x9qq-236j-gj97 | CVE-DB