<a id="ref-release-notes-4-0-11"></a>

# LXD 4.0.11 release notes

This is a [LTS release](https://canonical.com/lxd/docs/latest/reference/releases-snap/index.html.md#ref-releases-lts) and is recommended for production use.

<a id="ref-release-notes-4-0-11-highlights"></a>

## Highlights

### Ubuntu Pro detection

LXD now detects whether the host system is attached to Ubuntu Pro and advertises this as a feature in the user agent string. This allows LXD to expose Pro-specific capabilities when running on a Pro-attached host.

<a id="ref-release-notes-4-0-11-bugfixes"></a>

## Bug fixes

The following bug fixes are included in this release.

- [<spellexception>Arbitrary file write on host via </spellexception>exec-output` symlink in crafted image (CVE-2026-48750)`](https://github.com/canonical/lxd/security/advisories/GHSA-9j25-mm2h-2f76)
- [<spellexception>Arbitrary file read+write on host via templates/ symlink in malicious image (CVE-2026-48752)</spellexception>](https://github.com/canonical/lxd/security/advisories/GHSA-jpf8-86f3-wp38)
- [<spellexception>Arbitrary file read+write on host via rootfs/ symlink in malicious image (CVE-2026-48749)</spellexception>](https://github.com/canonical/lxd/security/advisories/GHSA-vghh-5rfx-xhq8)
- [<spellexception>Argument injection in backup compression algorithm leading to AFW and ACE (CVE-2026-48755)</spellexception>](https://github.com/canonical/lxd/security/advisories/GHSA-fmc8-p6q7-75cc)
- [<spellexception>Arbitrary file write on client due to trusted image hash (CVE-2026-48769)</spellexception>](https://github.com/canonical/lxd/security/advisories/GHSA-pjff-c2wc-f6jm)
- [<spellexception>Panic when importing backup configs that contain nil slices (CVE-2026-40197)</spellexception>](https://github.com/lxc/incus/security/advisories/GHSA-r7w7-mmxr-47r9)
- [<spellexception>Template sandbox escapes and crash risks in pongo2 rendering (CVE-2026-33897)</spellexception>](https://github.com/lxc/incus/security/advisories/GHSA-83xr-5xxr-mh92)
- [<spellexception>Overly permissive storage pool volume directory permissions expose instance data (CVE-2025-64507)</spellexception>](https://github.com/lxc/incus/security/advisories/GHSA-56mx-8g9f-5crf)
- [<spellexception>Potential shell expansion in LXC hook arguments due to incorrect quoting</spellexception>](https://github.com/lxc/incus/pull/2827)
- [<spellexception>Improve validation when editing certificates to reject invalid or inconsistent configurations</spellexception>](https://github.com/canonical/lxd/pull/17954)
- [<spellexception>Add raw.apparmor and raw.qemu.conf to the list of forbidden low-level options when low-level configuration is restricted in project limits</spellexception>](https://github.com/canonical/lxd/pull/17939)
- [<spellexception>Fail fast when an unsupported compression algorithm is specified for backup or image operations</spellexception>](https://github.com/canonical/lxd/pull/17821)
- [<spellexception>Fix panics when importing backups with missing or invalid configuration data</spellexception>](https://github.com/canonical/lxd/pull/15168)
- [<spellexception>Fix AppArmor rules for unprivileged containers to allow devpts, procfs, and sysfs mounts</spellexception>](https://github.com/canonical/lxd/pull/15109)

<a id="ref-release-notes-4-0-11-incompatible"></a>

## Backwards-incompatible changes

These changes are not compatible with older versions of LXD or its clients.

<a id="ref-release-notes-4-0-11-secureboot"></a>

### Secure Boot compatibility limitations (Microsoft 2023 CA rotation)

LXD 4.0 LTS bundles Microsoft UEFI 2011 CAs that [expired in June 2026](https://discourse.ubuntu.com/t/microsoft-uefi-ca-rotation-what-it-means-for-ubuntu-users-and-vendors/82652). Because LXD 4.0 LTS is out of standard support and ships an older EDK2 firmware utilizing a legacy 2MB flash layout, it will not receive updates to support the new Microsoft 2023 CAs. Due to this 2MB firmware size constraint, LXD 4.0 LTS already has [limited compatibility with modern guests that require Secure Boot](https://bugs.launchpad.net/ubuntu/+source/edk2/+bug/1885662).

**Implications:**
Virtual machine images using a boot loader signed exclusively with the 2023 CA will fail Secure Boot validation and refuse to boot.

**Workaround:**
Secure Boot enforcement might need to be disabled for the instance:

```bash
lxc config set <instance_name> security.secureboot false
```

### Minimum system requirement changes

The minimum supported version of some components has changed:

- The minimum required version of Go to build LXD is now 1.18 (see [Updated minimum Go version]()).

<a id="ref-release-notes-4-0-11-go"></a>

## Updated minimum Go version

If you are building LXD from source instead of using a package manager, the minimum version of Go required to build LXD is now 1.18.

<a id="ref-release-notes-4-0-11-changelog"></a>

## Change log

View the [complete list of all changes in this release](https://github.com/canonical/lxd/compare/lxd-4.0.10...lxd-4.0.11).

<a id="ref-release-notes-4-0-11-downloads"></a>

## Downloads

The source tarballs and binary clients can be found on our [download page](https://github.com/canonical/lxd/releases/tag/lxd-4.0.11).

Binary packages are also available for:

- **Linux:** `snap install lxd --channel=4.0/stable`
- **macOS client:** `brew install lxc`
- **Windows client:** `choco install lxc`
