๐Ÿ” CVE Alert

CVE-2026-52727

HIGH 7.2

lxc-ci: Pacman keyring stored in archlinux image with a private key

CVSS Score
7.2
EPSS Score
0.0%
EPSS Percentile
0th

lxc-ci contains continuous integration and image-build scripts for LXC. Prior to the 2026-05-28 Arch Linux image publication, images built from images/archlinux.yaml retain the same pacman local-signing private key in /etc/pacman.d/gnupg and redistribute it to every container or virtual machine created from that image. An attacker who controls an HTTP package mirror or can intercept mirror traffic can use the shared pacman signing private key to sign modified packages that affected clients accept as trusted. Installing those packages permits arbitrary code execution as root on the client system. This issue is fixed in Arch Linux images published on or after 2026-05-28.

CWE CWE-321
Vendor lxc
Product lxc-ci
Published Sep 17, 2026
Last Updated Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for lxc lxc-ci

Be the first to know when new high vulnerabilities affecting lxc lxc-ci are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

lxc / lxc-ci
< 2026-05-28

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/lxc/lxc-ci/security/advisories/GHSA-4h59-f67g-5qxp github.com: https://github.com/lxc/lxc-ci/commit/082cb34ea19791a0424feafd9da67b94881ea40a