{"id":"GO-2026-5368","summary":"VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf in github.com/canonical/lxd","details":"VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf in github.com/canonical/lxd","aliases":["CVE-2026-34177","GHSA-fm2x-c5qw-4h6f"],"modified":"2026-08-11T23:45:12.038719035Z","published":"2026-08-11T23:21:27Z","database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-5368"},"references":[{"type":"ADVISORY","url":"https://github.com/canonical/lxd/security/advisories/GHSA-fm2x-c5qw-4h6f"},{"type":"FIX","url":"https://github.com/canonical/lxd/pull/17909"}],"affected":[{"package":{"name":"github.com/canonical/lxd","ecosystem":"Go","purl":"pkg:golang/github.com/canonical/lxd"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.0.0-20210305023314-538ac3df036e"}]}],"ecosystem_specific":{"imports":[{"symbols":["CheckLimits"],"path":"github.com/canonical/lxd/lxd/project/limits"}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-5368.json"}}],"schema_version":"1.9.0"}