CVE-2024-6156

Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*
cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*

History

26 Aug 2025, 17:22

Type Values Removed Values Added
References () https://github.com/canonical/lxd/security/advisories/GHSA-4c49-9fpc-hc3v - () https://github.com/canonical/lxd/security/advisories/GHSA-4c49-9fpc-hc3v - Exploit, Vendor Advisory
References () https://www.cve.org/CVERecord?id=CVE-2024-6156 - () https://www.cve.org/CVERecord?id=CVE-2024-6156 - Third Party Advisory
First Time Canonical lxd
Canonical
CPE cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*

18 Mar 2025, 16:15

Type Values Removed Values Added
CWE CWE-295
Summary
  • (es) Mark Laing descubrió que el modo PKI de LXD, hasta la versión 5.21.2, podía eludirse si el certificado del cliente estaba presente en el almacén de confianza.

06 Dec 2024, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-06 00:15

Updated : 2025-08-26 17:22


NVD link : CVE-2024-6156

Mitre link : CVE-2024-6156

CVE.ORG link : CVE-2024-6156


JSON object : View

Products Affected

canonical

  • lxd
CWE
CWE-295

Improper Certificate Validation