lxd has a restricted TLS certificate privilege escalation when in PKI mode (CVE-2024-6219)
LXD in PKI mode with a server.ca file present does not honor restrictions on TLS client certificates when the core.trust_ca_certificates option is set to false. This allows clients with restricted certificates to gain full access to LXD, bypassing intended privilege limitations. The issue arises from a logic flaw in how certificate restrictions are enforced in PKI mode. The vulnerability is considered low impact because PKI mode is not the default and users enabling it typically enable core.trust_ca_certificates, which grants full access to all CA-signed clients anyway.
AI Analysis
Technical Summary
LXD's PKI mode activates when a server.ca file is present in LXD_DIR at startup, requiring clients to present CA-signed certificates. The configuration option core.trust_ca_certificates defaults to false, meaning certificate restrictions should be enforced. However, due to a flaw introduced during authorization refactoring, restricted client certificates are not honored and are granted full access to LXD when core.trust_ca_certificates is false. A cherry-pick fix addressed the issue when core.trust_ca_certificates is true but did not fix the false case. This results in privilege escalation for restricted certificates in PKI mode. The vulnerability is tracked as CVE-2024-6219.
Potential Impact
Clients with restricted TLS certificates can bypass their restrictions and gain full access to LXD when PKI mode is enabled and core.trust_ca_certificates is false. This leads to unauthorized privilege escalation within LXD. However, the impact is mitigated by the fact that PKI mode is not the default configuration and users enabling it generally enable core.trust_ca_certificates, which grants full access to all CA-signed clients anyway.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Users should verify their LXD configuration, especially the core.trust_ca_certificates setting, and avoid running LXD in PKI mode with core.trust_ca_certificates set to false. Monitor official LXD releases and advisories for patches addressing this issue. The vendor has applied a partial fix for the case when core.trust_ca_certificates is true, but the false case remains unaddressed.
lxd has a restricted TLS certificate privilege escalation when in PKI mode (CVE-2024-6219)
Description
LXD in PKI mode with a server.ca file present does not honor restrictions on TLS client certificates when the core.trust_ca_certificates option is set to false. This allows clients with restricted certificates to gain full access to LXD, bypassing intended privilege limitations. The issue arises from a logic flaw in how certificate restrictions are enforced in PKI mode. The vulnerability is considered low impact because PKI mode is not the default and users enabling it typically enable core.trust_ca_certificates, which grants full access to all CA-signed clients anyway.
CVSS v3.1
Score 3.8low
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
LXD's PKI mode activates when a server.ca file is present in LXD_DIR at startup, requiring clients to present CA-signed certificates. The configuration option core.trust_ca_certificates defaults to false, meaning certificate restrictions should be enforced. However, due to a flaw introduced during authorization refactoring, restricted client certificates are not honored and are granted full access to LXD when core.trust_ca_certificates is false. A cherry-pick fix addressed the issue when core.trust_ca_certificates is true but did not fix the false case. This results in privilege escalation for restricted certificates in PKI mode. The vulnerability is tracked as CVE-2024-6219.
Potential Impact
Clients with restricted TLS certificates can bypass their restrictions and gain full access to LXD when PKI mode is enabled and core.trust_ca_certificates is false. This leads to unauthorized privilege escalation within LXD. However, the impact is mitigated by the fact that PKI mode is not the default configuration and users enabling it generally enable core.trust_ca_certificates, which grants full access to all CA-signed clients anyway.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Users should verify their LXD configuration, especially the core.trust_ca_certificates setting, and avoid running LXD in PKI mode with core.trust_ca_certificates set to false. Monitor official LXD releases and advisories for patches addressing this issue. The vendor has applied a partial fix for the case when core.trust_ca_certificates is true, but the false case remains unaddressed.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-jpmc-7p9c-4rxf
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2024-6219"]
- Ecosystems
- ["Go"]
- Database Specific Severity
- LOW
- Cvss Version
- 3.1
Threat ID: 6a3ef78c27e9c79719ff489d
Added to database: 06/26/2026, 22:05:00 UTC
Last enriched: 06/26/2026, 22:15:03 UTC
Last updated: 09/10/2026, 19:36:49 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.