CVE Vulnerabilities

CVE-2024-6156

Improper Certificate Validation

Published: Dec 06, 2024 | Modified: Aug 26, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Mark Laing discovered that LXDs PKI mode, until version 5.21.2, could be bypassed if the clients certificate was present in the trust store.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
LxdCanonical4.0.0 (including)4.0.10 (excluding)
LxdCanonical5.0.0 (including)5.0.4 (excluding)
LxdCanonical5.1 (including)5.21.2 (excluding)
LxdUbuntufocal*

Potential Mitigations

References