CVE-2024-6156

Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*

History

26 Aug 2025, 17:22

Type Values Removed Values Added
First Time Canonical
Canonical lxd
References () https://github.com/canonical/lxd/security/advisories/GHSA-4c49-9fpc-hc3v - () https://github.com/canonical/lxd/security/advisories/GHSA-4c49-9fpc-hc3v - Exploit, Vendor Advisory
References () https://www.cve.org/CVERecord?id=CVE-2024-6156 - () https://www.cve.org/CVERecord?id=CVE-2024-6156 - Third Party Advisory
CPE cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*

18 Mar 2025, 16:15

Type Values Removed Values Added
Summary
  • (es) Mark Laing descubrió que el modo PKI de LXD, hasta la versión 5.21.2, podía eludirse si el certificado del cliente estaba presente en el almacén de confianza.
CWE CWE-295

06 Dec 2024, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-06 00:15

Updated : 2025-08-26 17:22


NVD link : CVE-2024-6156

Mitre link : CVE-2024-6156

CVE.ORG link : CVE-2024-6156


JSON object : View

Products Affected

canonical

  • lxd
CWE
CWE-295

Improper Certificate Validation