Medium severity6.5GHSA Advisory· Published May 7, 2026· Updated May 7, 2026
CVE-2026-41647
CVE-2026-41647
Description
Incus is a system container and virtual machine manager. Prior to version 7.0.0, a missing error handling could lead an authenticated Incus user to cause a daemon crash through the import of a truncated storage bucket backup file. This issue has been patched in version 7.0.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/lxc/incus/v6/cmd/incusdGo | <= 6.23.0 | — |
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/lxc/incus/releases/tag/v7.0.0nvdPatchProductWEB
- github.com/lxc/incus/security/advisories/GHSA-fwj8-62r8-8p8mnvdExploitMitigationVendor AdvisoryWEB
- github.com/advisories/GHSA-fwj8-62r8-8p8mghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-41647ghsaADVISORY
News mentions
0No linked articles in our index yet.