Mageia 9 LXC CVE-2026-39402 Insufficient Validation Vulnerability

Mageia 9 LXC CVE-2026-39402 Insufficient Validation Vulnerability

First seen 4 Jun 2026, 12:52 UTC Linuxsecurity 78% similarity 57.8

Article Content

Browse articles
ThreatCluster

CVE-2026-39402, affecting Mageia 9's LXC component, allows insufficient ownership validation, enabling cross-tenant OVS port deletion. This vulnerability poses a significant risk as it could allow unauthorized users to manipulate network resources. The flaw was published on May 5, 2026, and affects systems running LXC version 5.0.3-1.1.mga9. Users are advised to apply patches to mitigate the risk. The advisory highlights the importance of validating user permissions in multi-tenant environments. Current status indicates that the vulnerability is known but may not yet be actively exploited. Organizations using Mageia 9 should prioritize updates to secure their systems.

Key Points: • CVE-2026-39402 allows cross-tenant OVS port deletion due to insufficient validation. • The vulnerability affects Mageia 9 systems running LXC version 5.0.3-1.1.mga9. • Patches are available, and users are urged to update to mitigate risks.

ThreatCluster AI

Timeline

2026-05-05
CVE-2026-39402 published
Mageia disclosed a vulnerability in LXC allowing cross-tenant OVS port deletion due to insufficient ownership validation.
Linuxsecurity
2026-06-04
Mageia 9 LXC vulnerability advisory released
Mageia issued an advisory urging users to apply patches for CVE-2026-39402 to prevent unauthorized access.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story