DEBIAN-CVE-2025-54292

Source
https://security-tracker.debian.org/tracker/CVE-2025-54292
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-54292.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2025-54292
Upstream
Withdrawn
2025-10-31T04:32:26.455394Z
Published
2025-10-02T10:15:39Z
Modified
2025-10-31T04:32:26.455394Z
Summary
[none]
Details

Path traversal in Canonical LXD LXD-UI versions before 6.5 and 5.21.4 on all platforms allows remote authenticated attackers to access or modify unintended resources via crafted resource names embedded in URL paths.

References

Affected packages

Debian:13 / incus

Package

Name
incus
Purl
pkg:deb/debian/incus?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*
6.0.4-2
6.0.4-3
6.0.5-1
6.0.5-2
6.14.0-1~exp1
6.15.0-1~exp1
6.16.0-1~exp1
6.17.0-1~exp1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-54292.json"

Debian:14 / incus

Package

Name
incus
Purl
pkg:deb/debian/incus?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*
6.0.4-2
6.0.4-3
6.0.5-1
6.0.5-2
6.14.0-1~exp1
6.15.0-1~exp1
6.16.0-1~exp1
6.17.0-1~exp1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-54292.json"

Debian:12 / lxd

Package

Name
lxd
Purl
pkg:deb/debian/lxd?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*
5.0.2-5
5.0.2-6
5.0.2+git20231211.1364ae4-1
5.0.2+git20231211.1364ae4-2
5.0.2+git20231211.1364ae4-3
5.0.2+git20231211.1364ae4-4
5.0.2+git20231211.1364ae4-5
5.0.2+git20231211.1364ae4-6
5.0.2+git20231211.1364ae4-7
5.0.2+git20231211.1364ae4-8
5.0.2+git20231211.1364ae4-9

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-54292.json"

Debian:13 / lxd

Package

Name
lxd
Purl
pkg:deb/debian/lxd?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*
5.0.2+git20231211.1364ae4-9

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-54292.json"