CVE Vulnerabilities

CVE-2024-6219

Improper Certificate Validation

Published: Dec 06, 2024 | Modified: Nov 13, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Mark Laing discovered in LXDs PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
LxdCanonical*5.21.1 (excluding)
LxdUbuntufocal*

Potential Mitigations

References