Bug#1103702: lxd: CVE-2024-6156

2025-04-27 Thread Moritz Mühlenhoff
On Sat, Apr 26, 2025 at 06:17:28PM +, Mathias Gibbens wrote: > control: severity -1 minor > control: tags -1 + wontfix > > Due to code changes/refactoring between LXD 5.0.4 and the snapshot of > 5.0.2 in Debian, an unreasonable amount of work would be required to > fix this minor issue. Lowe

Bug#1103702: lxd: CVE-2024-6156

2025-04-26 Thread Mathias Gibbens
control: severity -1 minor control: tags -1 + wontfix Due to code changes/refactoring between LXD 5.0.4 and the snapshot of 5.0.2 in Debian, an unreasonable amount of work would be required to fix this minor issue. Lowering severity and tagging with "wontfix" to reflect this. Mathias On Fri, 2

Bug#1103702: lxd: CVE-2024-6156

2025-04-20 Thread Moritz Mühlenhoff
Source: lxd X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for lxd. CVE-2024-6156[0]: | Mark Laing discovered that LXD's PKI mode, until version 5.21.2, | could be bypassed if the client's certificate was present in the | t