Skip to main content
EPSS 0.2%top 95%

lxd has a restricted TLS certificate privilege escalation when in PKI mode (CVE-2024-6219)

0
Low
Published: 12/09/2024 (12/09/2024, 22:43:13 UTC)
Source: GCVE Database
Product: github.com/canonical/lxd

Description

LXD in PKI mode with a server.ca file present does not honor restrictions on TLS client certificates when the core.trust_ca_certificates option is set to false. This allows clients with restricted certificates to gain full access to LXD, bypassing intended privilege limitations. The issue arises from a logic flaw in how certificate restrictions are enforced in PKI mode. The vulnerability is considered low impact because PKI mode is not the default and users enabling it typically enable core.trust_ca_certificates, which grants full access to all CA-signed clients anyway.

CVSS v3.1

Score 3.8low

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
None
Availability
None
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Affected software

Goghsa
github.com/canonical/lxd
Affected versions
<0.0.0-20240403103450-0e7f2b5bf4d2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/26/2026, 22:15:03 UTC

Technical Analysis

LXD's PKI mode activates when a server.ca file is present in LXD_DIR at startup, requiring clients to present CA-signed certificates. The configuration option core.trust_ca_certificates defaults to false, meaning certificate restrictions should be enforced. However, due to a flaw introduced during authorization refactoring, restricted client certificates are not honored and are granted full access to LXD when core.trust_ca_certificates is false. A cherry-pick fix addressed the issue when core.trust_ca_certificates is true but did not fix the false case. This results in privilege escalation for restricted certificates in PKI mode. The vulnerability is tracked as CVE-2024-6219.

Potential Impact

Clients with restricted TLS certificates can bypass their restrictions and gain full access to LXD when PKI mode is enabled and core.trust_ca_certificates is false. This leads to unauthorized privilege escalation within LXD. However, the impact is mitigated by the fact that PKI mode is not the default configuration and users enabling it generally enable core.trust_ca_certificates, which grants full access to all CA-signed clients anyway.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Users should verify their LXD configuration, especially the core.trust_ca_certificates setting, and avoid running LXD in PKI mode with core.trust_ca_certificates set to false. Monitor official LXD releases and advisories for patches addressing this issue. The vendor has applied a partial fix for the case when core.trust_ca_certificates is true, but the false case remains unaddressed.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-jpmc-7p9c-4rxf
Osv Schema Version
1.4.0
Aliases
["CVE-2024-6219"]
Ecosystems
["Go"]
Database Specific Severity
LOW
Cvss Version
3.1

Threat ID: 6a3ef78c27e9c79719ff489d

Added to database: 06/26/2026, 22:05:00 UTC

Last enriched: 06/26/2026, 22:15:03 UTC

Last updated: 09/10/2026, 19:36:49 UTC

Views: 14

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses