<a id="ref-release-notes-5-0-7"></a>

# LXD 5.0.7 release notes

This is a [LTS release](https://canonical.com/lxd/docs/latest/reference/releases-snap/index.html.md#ref-releases-lts) and is recommended for production use.

This is a maintenance release for the 5.0 LTS series. It focuses on security hardening, stricter input validation, and bug fixes backported from the main development branch.

<a id="ref-release-notes-5-0-7-highlights"></a>

## Highlights

This section highlights notable improvements in this release.

### Security hardening

A number of inputs are now validated more strictly and some low-level options have been further restricted as part of security hardening backports:

- Stricter image fingerprint validation, including computing and verifying the combined hash during image downloads.
- Stricter validation of low-level VM options: `raw.apparmor` and `raw.qemu.conf` were added to the list of forbidden low-level options.
- Improved validation when editing certificates.
- Validation of struct slices and configuration during backup import.
- Tightened the compression algorithm validation to only allow supported values.

### Template rendering hardening

The instance template rendering logic was reworked to align with the standard `RenderTemplate` implementation. This introduces a recursion limit, blocks some `pongo2` template functions, handles panics from the `pongo2` package, and avoids leaking output from failed template execution.

<a id="ref-release-notes-5-0-7-bugfixes"></a>

## Bug fixes

The following bug fixes are included in this release.

- [<spellexception>Project restriction bypass in instance copy across projects (CVE-2026-55622)</spellexception>](https://github.com/canonical/lxd/security/advisories/GHSA-qx75-2p3r-pwm5)
- [<spellexception>Project restriction bypass for custom volume copy across projects (CVE-2026-55621)</spellexception>](https://github.com/canonical/lxd/security/advisories/GHSA-7mr3-28h5-m5vx)
- [<spellexception>Restricted project bypass leading to arbitrary command execution (CVE-2026-48751)</spellexception>](https://github.com/canonical/lxd/security/advisories/GHSA-47w9-6r3f-938g)
- [<spellexception>Arbitrary file write on host via </spellexception>exec-output` symlink in crafted image (CVE-2026-48750)`](https://github.com/canonical/lxd/security/advisories/GHSA-9j25-mm2h-2f76)
- [<spellexception>Arbitrary file read+write on host via templates/ symlink in malicious image (CVE-2026-48752)</spellexception>](https://github.com/canonical/lxd/security/advisories/GHSA-jpf8-86f3-wp38)
- [<spellexception>Arbitrary file read+write on host via rootfs/ symlink in malicious image (CVE-2026-48749)</spellexception>](https://github.com/canonical/lxd/security/advisories/GHSA-vghh-5rfx-xhq8)
- [<spellexception>Argument injection in backup compression algorithm leading to AFW and ACE (CVE-2026-48755)</spellexception>](https://github.com/canonical/lxd/security/advisories/GHSA-fmc8-p6q7-75cc)
- [<spellexception>Arbitrary file write on client due to trusted image hash (CVE-2026-48769)</spellexception>](https://github.com/canonical/lxd/security/advisories/GHSA-pjff-c2wc-f6jm)
- [<spellexception>Backup snapshot import bypasses project restrictions (CVE-2026-9640)</spellexception>](https://github.com/canonical/lxd/security/advisories/GHSA-ppq7-4492-5552)
- [<spellexception>Compute and verify combined hash during image downloads</spellexception>](https://github.com/canonical/lxd/pull/17994)
- [<spellexception>Validate all backup config slices for nil values</spellexception>](https://github.com/canonical/lxd/pull/18227)
- [<spellexception>Validate backup .Config</spellexception>](https://github.com/canonical/lxd/pull/18227)
- [<spellexception>Do not persist changes in UpdateInstanceConfig during import</spellexception>](https://github.com/canonical/lxd/pull/17968)
- [<spellexception>Do not use backup config from disk in internalImportFromBackup</spellexception>](https://github.com/canonical/lxd/pull/17968)
- [<spellexception>Always exclude backup config from the generic VFS tarball</spellexception>](https://github.com/canonical/lxd/pull/17968)
- [<spellexception>Validate whether instance snapshot can be created in createFromBackup</spellexception>](https://github.com/canonical/lxd/pull/18304)
- [<spellexception>Quote architecture name supplied in shared/osarch</spellexception>](https://github.com/canonical/lxd/pull/18304)
- [<spellexception>Do not bypass the instance limit check</spellexception>](https://github.com/canonical/lxd/pull/17991)
- [<spellexception>Fail fast if the compression algorithm is unsupported for images, instance backups, and storage volume backups</spellexception>](https://github.com/canonical/lxd/pull/17820)
- [<spellexception>Capture panics from pongo2 during template rendering</spellexception>](https://github.com/canonical/lxd/pull/17980)
- [<spellexception>Introduce a recursion limit to RenderTemplate()</spellexception>](https://github.com/canonical/lxd/pull/17980)
- [<spellexception>Block some pongo2 functions in templates</spellexception>](https://github.com/canonical/lxd/pull/17980)

<a id="ref-release-notes-5-0-7-incompatible"></a>

## Backwards-incompatible changes

These changes are not compatible with older versions of LXD or its clients.

### Minimum system requirement changes

The minimum supported version of some components has changed:

- The minimum required version of Go to build LXD is now 1.25.8 (see [Updated minimum Go version]()).

### Stricter validation and tightened permissions

Several inputs are now validated more strictly, and some low-level options have been further restricted as part of security hardening backports. Requests that previously succeeded with malformed or unexpected values may now be rejected:

- Stricter image fingerprint validation.
- Stricter checks for low-level (`raw.*`) VM configuration options, including `raw.apparmor` and `raw.qemu.conf`.
- Improved certificate edit validation.
- Validation of struct slices and configuration during import.
- The compression algorithm validation now only allows supported values.

<a id="ref-release-notes-5-0-7-go"></a>

## Updated minimum Go version

If you are building LXD from source instead of using a package manager, the minimum version of Go required to build LXD is now 1.26.4 (previously 1.24.6).

<a id="ref-release-notes-5-0-7-snap"></a>

## Snap packaging changes

- Transitioned the snap base from `core20` to `core22`.
- QEMU is now built from the Ubuntu source package (`8.2.2+ds-0ubuntu1.17`) instead of upstream Git.
- Added an edk2/OVMF patch to disable the UEFI shell when Secure Boot is enabled.
- Added the `apparmor.unprivileged-restrictions-disable` snap configuration option (default `true`).
- The `lxd-ui` build now uses Node.js 20 (previously 18).
- Refreshed the bundled Ceph stage libraries for `core22`.
- libnvidia-container bumped to v1.19.1.
- ZFS 2.2 bumped to 2.2.10.

<a id="ref-release-notes-5-0-7-changelog"></a>

## Change log

View the [complete list of all changes in this release](https://github.com/canonical/lxd/compare/lxd-5.0.6...lxd-5.0.7).

<a id="ref-release-notes-5-0-7-downloads"></a>

## Downloads

The source tarballs and binary clients can be found on our [download page](https://github.com/canonical/lxd/releases/tag/lxd-5.0.7).

Binary packages are also available for:

- **Linux:** `snap install lxd --channel=5.0/stable`
- **macOS client:** `brew install lxc`
- **Windows client:** `choco install lxc`
