<a id="ref-release-notes-5-0-8"></a>

# LXD 5.0.8 release notes

This is a [LTS release](https://canonical.com/lxd/docs/latest/reference/releases-snap/index.html.md#ref-releases-lts) and is recommended for production use.

This is a maintenance release for the 5.0 LTS series. It focuses on updating the bundled UEFI firmware and snap packaging, along with build and tooling changes backported from the main development branch.

<a id="ref-release-notes-5-0-8-highlights"></a>

## Highlights

This section highlights notable improvements in this release.

### Updated UEFI firmware (EDK2/OVMF)

The bundled EDK2/OVMF firmware used for virtual machines has been refreshed and modernized:

- The EDK2 sources now build from the Ubuntu Noble (`core24`) source package, replacing the previous custom build.
- The firmware was bumped to `2024.02-2ubuntu0.9`, which ships the Microsoft 2023 Secure Boot keys.
- OVMF firmware is now shipped using the `4MB` file names (`OVMF_CODE.4MB.fd`, `OVMF_VARS.4MB.fd`, `OVMF_VARS.4MB.ms.fd`).
- The QEMU driver now detects the installed UEFI firmware for feature checks, always refreshes the `qemu.nvram` symlink, and regenerates the NVRAM when a virtual machine transitions to the new 4MB firmware. This ensures existing virtual machines pick up the updated firmware cleanly on next start.

<a id="ref-release-notes-5-0-8-incompatible"></a>

## Backwards-incompatible changes

These changes are not compatible with older versions of LXD or its clients.

### Minimum system requirement changes

The minimum supported version of some components has changed:

- The minimum required version of Go to build LXD is now 1.26.5 (see [Updated minimum Go version]()).

<a id="ref-release-notes-5-0-8-go"></a>

## Updated minimum Go version

If you are building LXD from source instead of using a package manager, the minimum version of Go required to build LXD is now 1.26.5 (previously 1.26.4).

<a id="ref-release-notes-5-0-8-snap"></a>

## Snap packaging changes

- The EDK2/OVMF part now builds from the Ubuntu Noble (`core24`) source package.
- Bumped EDK2/OVMF to `2024.02-2ubuntu0.9`, which includes the Microsoft 2023 Secure Boot keys, and switched to the 4MB CODE firmware layout.
- Synced the EDK2 boot logo with `latest-edge`.
- Dropped the now unused `qemu-ovmf-secureboot` part and the standalone `nasm` part (and its patch).
- Dropped unused EDK2 patches.

<a id="ref-release-notes-5-0-8-bugfixes"></a>

## Bug fixes

The following bug fixes are included in this release.

- [<spellexception>Arbitrary file read and write via image metadata.yaml symlink (CVE-2026-63293)</spellexception>](https://github.com/canonical/lxd/security/advisories/GHSA-j825-cg34-5fr5)
- [<spellexception>Root command execution via image backup.yaml symlink (CVE-2026-63294)</spellexception>](https://github.com/canonical/lxd/security/advisories/GHSA-fv82-v4fj-mm4m)
- [<spellexception>NVIDIA configuration validation bypass for nvidia.driver.capabilities (CVE-2026-63298)</spellexception>](https://github.com/canonical/lxd/security/advisories/GHSA-vfh7-q59q-54v2)
- [<spellexception>Restricted project bypass for security.idmap.isolated defaults (CVE-2026-63295)</spellexception>](https://github.com/canonical/lxd/security/advisories/GHSA-7vp9-3vmp-c5jm)
- [<spellexception>Project restriction bypass via instance migration config override (CVE-2026-63296)</spellexception>](https://github.com/canonical/lxd/security/advisories/GHSA-gcr9-5q6r-w625)
- [<spellexception>Cross-project instance copy bypass via config merge timing (CVE-2026-63297)</spellexception>](https://github.com/canonical/lxd/security/advisories/GHSA-v989-qw7w-xvg4)
- [<spellexception>Storage volume cross-project move and restore bypass project disk limits (CVE-2026-63299)</spellexception>](https://github.com/canonical/lxd/security/advisories/GHSA-5h78-p252-989h)
- [<spellexception>Cross-project cluster migration bypasses project restrictions (CVE-2026-62420)</spellexception>](https://github.com/canonical/lxd/security/advisories/GHSA-v9wr-9r7q-fh4g)
- [<spellexception>Cross-project instance move bypasses project restrictions (CVE-2026-63300)</spellexception>](https://github.com/canonical/lxd/security/advisories/GHSA-5g5r-wh97-qcq2)

<a id="ref-release-notes-5-0-8-changelog"></a>

## Change log

View the [complete list of all changes in this release](https://github.com/canonical/lxd/compare/lxd-5.0.7...lxd-5.0.8).

<a id="ref-release-notes-5-0-8-downloads"></a>

## Downloads

The source tarballs and binary clients can be found on our [download page](https://github.com/canonical/lxd/releases/tag/lxd-5.0.8).

Binary packages are also available for:

- **Linux:** `snap install lxd --channel=5.0/stable`
- **macOS client:** `brew install lxc`
- **Windows client:** `choco install lxc`
