<a id="ref-release-notes-4-0-12"></a>

# LXD 4.0.12 release notes

This is a [LTS release](https://canonical.com/lxd/docs/latest/reference/releases-snap/index.html.md#ref-releases-lts) and is recommended for production use.

This is a maintenance release for the 4.0 LTS series. It focuses on security hardening, stricter input validation, and bug fixes backported from the main development branch.

<a id="ref-release-notes-4-0-12-highlights"></a>

## Highlights

This section highlights notable improvements in this release.

### Security hardening for image and backup handling

Several hardening fixes were backported to reduce archive and template-related attack surface:

- Reject non-regular metadata files after unpack.
- Reject unconfined backup metadata.
- Prevent instance templates from escaping the templates directory.
- Validate backup instance and volume names during import.

### NVIDIA configuration validation improvements

Validation for NVIDIA-related instance configuration was tightened and applied consistently at set time and start time. This includes stricter validation for `nvidia.driver.capabilities`, `nvidia.require.cuda`, and `nvidia.require.driver`.

<a id="ref-release-notes-4-0-12-bugfixes"></a>

## Bug fixes

The following bug fixes are included in this release.

- [<spellexception>Arbitrary file read and write via image metadata.yaml symlink (CVE-2026-63293)</spellexception>](https://github.com/canonical/lxd/security/advisories/GHSA-j825-cg34-5fr5)
- [<spellexception>NVIDIA configuration validation bypass for nvidia.require.\* and nvidia.driver.capabilities (CVE-2026-63298)</spellexception>](https://github.com/canonical/lxd/security/advisories/GHSA-vfh7-q59q-54v2)
- [<spellexception>Restricted project bypass for security.idmap.isolated defaults (CVE-2026-63295)</spellexception>](https://github.com/canonical/lxd/security/advisories/GHSA-7vp9-3vmp-c5jm)
- [<spellexception>Unconfined backup.yaml accepted after unpack in crafted backups (CVE-2026-63294)</spellexception>](https://github.com/canonical/lxd/security/advisories/GHSA-fv82-v4fj-mm4m)
- [<spellexception>Prevent image metadata templates from escaping the instance directory (CVE-2026-16033)</spellexception>](https://github.com/canonical/lxd/security/advisories/GHSA-9hcm-hxh5-7xxh)
- [<spellexception>Validate backup import names to prevent path traversal during restore (CVE-2026-66898)</spellexception>](https://github.com/canonical/lxd/security/advisories/GHSA-m857-c7gc-c984)

<a id="ref-release-notes-4-0-12-changelog"></a>

## Change log

View the [complete list of all changes in this release](https://github.com/canonical/lxd/compare/lxd-4.0.11...lxd-4.0.12).

<a id="ref-release-notes-4-0-12-downloads"></a>

## Downloads

The source tarballs and binary clients can be found on our [download page](https://github.com/canonical/lxd/releases/tag/lxd-4.0.12).

Binary packages are also available for:

- **Linux:** `snap install lxd --channel=4.0/stable`
- **macOS client:** `brew install lxc`
- **Windows client:** `choco install lxc`
