rpm package
opensuse/incus&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/incus&distro=openSUSE%20Tumbleweed
Vulnerabilities (30)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-63343 | Cri | 9.9 | < 7.4-1.1 | 7.4-1.1 | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an authenticated Incus user to read or overwrite any file on the host as root via the instance metadat | |
| CVE-2026-63125 | Cri | 9.9 | < 7.4-1.1 | 7.4-1.1 | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and `can_create_instances`) can execute arbitrary code as root on the host. A crafted image ships | |
| CVE-2026-62941 | Cri | 9.9 | < 7.4-1.1 | 7.4-1.1 | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCreation`) runs BEFORE the source instance's configuration is merged into the request. Dangerous configuration k | |
| CVE-2026-62940 | Cri | 9.9 | < 7.4-1.1 | 7.4-1.1 | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluster member, user-supplied configuration overrides (including security-critical keys like `security.privileged` and `raw.lxc`) are applied without any project | |
| CVE-2026-62867 | Cri | 9.9 | < 7.4-1.1 | 7.4-1.1 | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration leads to argument injection in the constructed filesystem creation command line. This allows a project-scop | |
| CVE-2026-62313 | Med | 4.3 | < 7.4-1.1 | 7.4-1.1 | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, project-level enforcement of `restricted.containers.privilege=isolated` can be trivially bypassed, allowing a user to create a non-isolated (shared host idmap) container in a project that is configur | |
| CVE-2026-55622 | Hig | 7.7 | < 7.4-1.1 | 7.4-1.1 | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name of an instance in that project can copy the instanc | |
| CVE-2026-55621 | Hig | 7.7 | < 7.4-1.1 | 7.4-1.1 | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for custom volume copying where an attacker knowing the name of a project that they don't have access to and the name of a custom volume in that project can copy th | |
| CVE-2026-48769 | Cri | 9.9 | < 7.4-1.1 | 7.4-1.1 | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary command execution as root on the server. Versi | |
| CVE-2026-48756 | Low | — | < 7.4-1.1 | 7.4-1.1 | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateCustomVolumeFromBackup` in `internal/server/storage/backend.go` contains an unguarded `*time.Time` dereference on the `ExpiresAt` field of every volume-snapshot entry in an imported | |
| CVE-2026-48755 | Cri | 9.9 | < 7.4-1.1 | 7.4-1.1 | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary file write on the host, possibly leading to a | |
| CVE-2026-48754 | Low | — | < 7.4-1.1 | 7.4-1.1 | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).createDependentVolumesFromBackup` in `internal/server/storage/backend.go` contains a cluster of unguarded pointer derefs on every dependent-volume entry's `VolumeSnapshots[i]`, `Volume`, | |
| CVE-2026-48753 | Cri | 9.9 | < 7.4-1.1 | 7.4-1.1 | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution. Version 7.1.0 fixes the is | |
| CVE-2026-48752 | Cri | 9.9 | < 7.4-1.1 | 7.4-1.1 | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 patches the issue. | |
| CVE-2026-48751 | Cri | 9.9 | < 7.4-1.1 | 7.4-1.1 | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on the Incus server by abusing lowlevel hooks such as `raw.lxc` and `raw.qemu`. | |
| CVE-2026-48750 | Cri | 9.9 | < 7.4-1.1 | 7.4-1.1 | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the instance. If `exec-output` is a symlink, file named `exec_ | |
| CVE-2026-48749 | Cri | 9.9 | < 7.4-1.1 | 7.4-1.1 | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 fixes the issue. | |
| CVE-2026-47753 | Med | — | < 7.4-1.1 | 7.4-1.1 | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateInstanceFromBackup` in `internal/server/storage/backend.go` contains a nil-pointer dereference that an authenticated user with permission to create instances in any project can trig | |
| CVE-2026-39402 | Med | 6.5 | < 7.4-1.1 | 7.4-1.1 | May 5, 2026 | lxc is a Linux container runtime. In the setuid helper lxc-user-nic, the delete path contains a logic flaw in the find_line() function that allows an unprivileged user to delete OVS-attached network interfaces belonging to other users. When lxc-user-nic delete scans its NIC datab | |
| CVE-2026-33945 | Cri | 9.9 | < 6.23-1.1 | 6.23-1.1 | Mar 27, 2026 | Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to systemd in the guest. For containers, this is handled through a shared directory. Prior to version 6.23.0, an attacker can set a configuration key named something lik |
- affected < 7.4-1.1fixed 7.4-1.1
Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an authenticated Incus user to read or overwrite any file on the host as root via the instance metadat
- affected < 7.4-1.1fixed 7.4-1.1
Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and `can_create_instances`) can execute arbitrary code as root on the host. A crafted image ships
- affected < 7.4-1.1fixed 7.4-1.1
Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCreation`) runs BEFORE the source instance's configuration is merged into the request. Dangerous configuration k
- affected < 7.4-1.1fixed 7.4-1.1
Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluster member, user-supplied configuration overrides (including security-critical keys like `security.privileged` and `raw.lxc`) are applied without any project
- affected < 7.4-1.1fixed 7.4-1.1
Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration leads to argument injection in the constructed filesystem creation command line. This allows a project-scop
- affected < 7.4-1.1fixed 7.4-1.1
Incus is a system container and virtual machine manager. Prior to version 7.3.0, project-level enforcement of `restricted.containers.privilege=isolated` can be trivially bypassed, allowing a user to create a non-isolated (shared host idmap) container in a project that is configur
- affected < 7.4-1.1fixed 7.4-1.1
Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name of an instance in that project can copy the instanc
- affected < 7.4-1.1fixed 7.4-1.1
Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for custom volume copying where an attacker knowing the name of a project that they don't have access to and the name of a custom volume in that project can copy th
- affected < 7.4-1.1fixed 7.4-1.1
Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary command execution as root on the server. Versi
- affected < 7.4-1.1fixed 7.4-1.1
Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateCustomVolumeFromBackup` in `internal/server/storage/backend.go` contains an unguarded `*time.Time` dereference on the `ExpiresAt` field of every volume-snapshot entry in an imported
- affected < 7.4-1.1fixed 7.4-1.1
Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary file write on the host, possibly leading to a
- affected < 7.4-1.1fixed 7.4-1.1
Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).createDependentVolumesFromBackup` in `internal/server/storage/backend.go` contains a cluster of unguarded pointer derefs on every dependent-volume entry's `VolumeSnapshots[i]`, `Volume`,
- affected < 7.4-1.1fixed 7.4-1.1
Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution. Version 7.1.0 fixes the is
- affected < 7.4-1.1fixed 7.4-1.1
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 patches the issue.
- affected < 7.4-1.1fixed 7.4-1.1
Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on the Incus server by abusing lowlevel hooks such as `raw.lxc` and `raw.qemu`.
- affected < 7.4-1.1fixed 7.4-1.1
Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the instance. If `exec-output` is a symlink, file named `exec_
- affected < 7.4-1.1fixed 7.4-1.1
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 fixes the issue.
- affected < 7.4-1.1fixed 7.4-1.1
Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateInstanceFromBackup` in `internal/server/storage/backend.go` contains a nil-pointer dereference that an authenticated user with permission to create instances in any project can trig
- affected < 7.4-1.1fixed 7.4-1.1
lxc is a Linux container runtime. In the setuid helper lxc-user-nic, the delete path contains a logic flaw in the find_line() function that allows an unprivileged user to delete OVS-attached network interfaces belonging to other users. When lxc-user-nic delete scans its NIC datab
- affected < 6.23-1.1fixed 6.23-1.1
Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to systemd in the guest. For containers, this is handled through a shared directory. Prior to version 6.23.0, an attacker can set a configuration key named something lik
Page 1 of 2