{"id":"openSUSE-SU-2026:21788-1","summary":"Security update for lxd","details":"This update for lxd fixes the following issues:\n\nChanges in lxd:\n\n- update to 5.21.6:\n  * bsc#1274937, CVE-2026-63293, bsc#1274936, CVE-2026-62420,\n    bsc#1274954, CVE-2026-63295, bsc#1274963, CVE-2026-63297,\n    bsc#1274961, CVE-2026-63296, bsc#1275085, CVE-2026-63299,\n    bsc#1275084, CVE-2026-63298, bsc#1275090, CVE-2026-66898\n  * https://canonical.com/lxd/docs/latest/reference/release-\n    notes/5.21/release-notes-5.21.6/\n  * https://canonical.com/lxd/docs/latest/reference/release-\n    notes/5.21/release-notes-5.21.5/\n  * https://discourse.ubuntu.com/t/lxd-5-21-4-lts-has-been-\n    released/66602\n  * https://discourse.ubuntu.com/t/lxd-5-21-3-lts-has-been-\n    released/53768\n  * https://discourse.ubuntu.com/t/lxd-5-21-2-has-been-\n    released/46443\n\n- Migrate to single LXD/Incus OVMF handling (lxd-ovmf-setup):\n  * Allow aarch64 arch_vm_support\n  * Remove OVMF symlinks\n  * Require the new lxd-ovmf-setup packages\n","modified":"2026-09-09T18:23:14.722302125Z","published":"2026-09-02T12:35:45Z","related":["CVE-2023-46565","CVE-2026-62420","CVE-2026-63293","CVE-2026-63295","CVE-2026-63296","CVE-2026-63297","CVE-2026-63298","CVE-2026-63299","CVE-2026-66898"],"upstream":["CVE-2023-46565","CVE-2026-62420","CVE-2026-63293","CVE-2026-63295","CVE-2026-63296","CVE-2026-63297","CVE-2026-63298","CVE-2026-63299","CVE-2026-66898"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1223794"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274936"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274937"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274954"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274961"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274963"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275084"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275085"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275090"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-46565"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-62420"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-63293"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-63295"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-63296"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-63297"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-63298"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-63299"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-66898"}],"affected":[{"package":{"name":"lxd","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/lxd&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.21.6-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"lxd-bash-completion":"5.21.6-bp160.1.1","lxd":"5.21.6-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21788-1.json"}}],"schema_version":"1.9.0"}