Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

No. For CVE-2026-87799, switching an LXD migration from rsync to optimized btrfs receive does not remove the vulnerability: Canonical says both receive paths can follow symlinks in incoming data and write outside the intended volume. The risk is on the privileged receiving host, so the priority is to install a fixed LXD build and restrict who can initiate migrations or create instances and custom volumes.

How rsync and Btrfs receive differ in this vulnerability

LXD can use different tools to apply migration data, depending on the transfer path. Standard receive paths use rsync; optimized transfers between Btrfs pools use btrfs receive. The tool changes, but the relevant weakness does not: Canonical says both can resolve incoming paths through symlinks and write entries outside the intended volume.

Receive path Where LXD uses it CVE-2026-87799 status Why
rsync Instance or custom-volume migration receive paths that use rsync Affected Incoming entries are written under the volume path. If parent directories are not transferred, path resolution can pass through a symlink created earlier in the transfer.
btrfs receive Optimized transfers between Btrfs pools Affected Stream operations, including file creation, writes, directory creation and renames, use ordinary path-based calls and are not verified against the real filesystem the stream was meant to describe.
zfs receive Optimized ZFS transfers Not affected by this CVE, according to Canonical Canonical says this receiver does not resolve host paths. This is a narrow statement about this vulnerability, not a general security guarantee for ZFS.

Canonical’s advisory describes the core issue this way: “Both tools replay the stream on the host using regular path-based system calls and follow symlinks in the paths they write to.” See the Canonical LXD advisory for its technical explanation.

What an attacker can do—and what access is needed

A malicious migration source can place a symlink such as rootfs pointing to /, then arrange later entries in the same stream—or a later snapshot or main-volume stream—to be written through that link. For a virtual machine, the advisory describes replacing root.img with a symlink before writing the block stream through it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The result can be arbitrary attacker-controlled file writes as root on the receiving host, with potential for full host compromise. Before LXD 7.3.0, the advisory also describes a rootfs symlink surviving transfer and then being followed by the file API during container chroot, creating a host-file read path as well as the write risk.

The issue is not described as an unauthenticated attack. The attacker needs permission to create instances or custom storage volumes in the target project, or control a source server that the target is instructed to copy or move from. The practical security boundary is therefore the trust placed in migration sources and the project permissions granted on the receiving LXD server.

Which LXD versions are affected and fixed?

Canonical’s advisory lists LXD versions >= 4.0 as affected and names these fixed upstream releases: 4.0.14, 5.0.10, 5.21.8, 6.9-bf243da and 6.10. It was published on 2026-09-25 and rates the issue Critical, CVSS 9.9. The score is a severity rating, not an estimate of how often exploitation has occurred.

Distribution package status can differ from upstream version numbering because vendors may backport fixes. Check the package advisory for the exact operating-system release and repository you use rather than assuming that an upstream version comparison settles whether your installed package is fixed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Ubuntu: The Ubuntu CVE page, published 2026-09-29 and updated 2026-09-30, also reports CVSS 9.9 Critical, while assigning Ubuntu priority Medium. At that time, Ubuntu 26.04, 24.04 and 22.04 were listed as “Not in release”; 20.04, 18.04 and 16.04 were listed as “Needs evaluation.” These are the page’s displayed statuses at that time, not a statement about other package sources or later updates.
  • Debian: The Debian Security Tracker, as accessed, listed Bookworm package 5.0.2-5+deb12u6 and Trixie package 5.0.2+git20231211.1364ae4-9+deb13u7 as vulnerable, and unstable as unfixed. Check the live tracker and your system’s package source for current status.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to do now

Install a fixed release or package

Update to an applicable fixed LXD upstream release or a distribution package that includes the vendor fix. Confirm the status for your own distribution and repository; upstream release numbers, downstream package versions and distribution security status are not interchangeable.

Limit migration and project permissions until patched

Canonical’s stated workaround is to allow only trusted clients to create instances and custom volumes, and to migrate only from trusted servers. Review which users and systems can perform those actions on the receiving host, and remove access that is not needed.

Do not treat a backend switch as remediation

Moving from rsync to optimized Btrfs receive leaves the described exposure in place. Canonical’s ZFS exception applies only to optimized ZFS transfers and this specific CVE; it is not a substitute for applying the fix or controlling who can send migration data.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.