CVE-2025-54288
CVE-2025-54288 is a medium-severity vulnerability in Canonical Lxd with a CVSS 3.x base score of 6.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-290.
Key facts
- Severity: Medium (CVSS 3.x base score 6.8)
- CVSS v4: 5.1
- EPSS exploit prediction: 0% (26th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2025-32637
- Weakness: CWE-290
- Affected product: Canonical Lxd
- Published:
- Last modified:
Description
Information Spoofing in devLXD Server in Canonical LXD versions 4.0 and above on Linux container platforms allows attackers with root privileges within any container to impersonate other containers and obtain their metadata, configuration, and device information via spoofed process names in the command line.
Frequently asked questions
- What is CVE-2025-54288?
- Information Spoofing in devLXD Server in Canonical LXD versions 4.0 and above on Linux container platforms allows attackers with root privileges within any container to impersonate other containers and obtain their metadata, configuration, and device information via spoofed process names in the command line.
- How severe is CVE-2025-54288?
- CVE-2025-54288 has a CVSS 3.x base score of 6.8, rated medium severity. It is exploitable over network with low attack complexity, requires high privileges and no user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2025-54288 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (26th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2025-54288?
- CVE-2025-54288 affects Canonical Lxd. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2025-54288?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2025-54288 have an EU (EUVD) identifier?
- Yes. CVE-2025-54288 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-32637.
- When was CVE-2025-54288 published?
- CVE-2025-54288 was published on 2025-10-02 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*
More vulnerabilities in Canonical Lxd
- CVE-2026-66897 — Critical (CVSS 9.9): A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit…
- CVE-2026-66898 — Critical (CVSS 9.9): A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and…
- CVE-2026-63300 — Critical (CVSS 9.9): An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an…
- CVE-2026-63299 — Critical (CVSS 9.9): An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume…
- CVE-2026-63298 — Critical (CVSS 9.9): An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an…
- CVE-2026-63297 — Critical (CVSS 9.9): An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated…
All CVEs affecting Canonical Lxd →
Other CWE-290 vulnerabilities
- CVE-2026-69843 — Critical (CVSS 10.0): Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a…
- CVE-2026-76423 — Critical (CVSS 10.0): A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain…
- CVE-2026-54782 — Critical (CVSS 10.0): CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1,…
- CVE-2026-48567 — Critical (CVSS 10.0): Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a…
- CVE-2026-6213 — Critical (CVSS 10.0): A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check…
- CVE-2026-39858 — Critical (CVSS 10.0): Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high…