CVE-2026-23954
published 2026-01-22CVE-2026-23954: Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom image (e.g…
PriorityP356high8.7CVSS 3.1
AVAACLPRLUINSCCHIHAN
EPSS
0.73%
50.0th percentile
Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom image (e.g a member of the ‘incus’ group) to use directory traversal or symbolic links in the templating functionality to achieve host arbitrary file read, and host arbitrary file write. This ultimately results in arbitrary command execution on the host. When using an image with a metadata.yaml containing templates, both the source and target paths are not checked for symbolic links or directory traversal. This can also be exploited in IncusOS. A fix is planned for versions 6.0.6 and 6.21.0, but they have not been released at the time of publication.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | lxd | >= 0 < 5.0.2-5+deb12u3 | 5.0.2-5+deb12u3 |
| canonical | lxd | >= 0 < 5.0.2+git20231211.1364ae4-9+deb13u3 | 5.0.2+git20231211.1364ae4-9+deb13u3 |
| debian | incus | < incus 6.0.5-8 (forky) | incus 6.0.5-8 (forky) |
| debian | lxd | < incus 6.0.5-8 (forky) | incus 6.0.5-8 (forky) |
| github.com | lxc_incus_v6 | >= 6.1.0 | — |
| linuxcontainers | incus | <= 6.0.5 | — |
| linuxcontainers | incus | >= 6.1.0 < 6.21.0 | 6.21.0 |
| lxc | incus | <= 6.0.5 | — |
| lxc | incus | — | — |
| lxc | incus | >= 0 < 6.0.4-2+deb13u4 | 6.0.4-2+deb13u4 |
| lxc | incus | >= 0 < 6.0.5-8 | 6.0.5-8 |
CVSS provenance
nvdv3.18.7HIGHCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
osv8.7HIGH
vendor_debian8.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2026-23954: incus - Incus is a system container and virtual machine manager. Versions 6.21.0 and bel...
vendor_debian·2026·CVSS 8.7
CVE-2026-23954 [HIGH] CVE-2026-23954: incus - Incus is a system container and virtual machine manager. Versions 6.21.0 and bel...
Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom image (e.g a member of the ‘incus’ group) to use directory traversal or symbolic links in the templating functionality to achieve host arbitrary file read, and host arbitrary file write. This ultimately results in arbitrary command execution on the host. When using an image with a metadata.yaml containing templates, both the source and target paths are not checked for symbolic links or directory traversal. This can also be exploited in IncusOS. A fix is planned for versions 6.0.6 and 6.21.0, but they have not been released at the time of publication.
Scope: local
forky: resolved (fixed in 6.0.5-8)
sid: resolved (fixed in 6.0.5-8)
trixie: resol
OSV
Incus container image templating arbitrary host file read and write in github.com/lxc/incus
osv·2026-02-05
CVE-2026-23954 Incus container image templating arbitrary host file read and write in github.com/lxc/incus
Incus container image templating arbitrary host file read and write in github.com/lxc/incus
Incus container image templating arbitrary host file read and write in github.com/lxc/incus
GHSA
Incus container image templating arbitrary host file read and write
ghsa·2026-01-22
CVE-2026-23954 [HIGH] CWE-22 Incus container image templating arbitrary host file read and write
Incus container image templating arbitrary host file read and write
### Summary
A user with the ability to launch a container with a custom image (e.g a member of the ‘incus’ group) can use directory traversal or symbolic links in the templating functionality to achieve host arbitrary file read, and host arbitrary file write, ultimately resulting in arbitrary command execution on the host. This can also be exploited in IncusOS.
### Details
When using an image with a `metadata.yaml` containing templates, both the source and target paths are not checked for symbolic links or directory traversal. [1] [2] For example, the following `metadata.yaml` snippet can read an arbitrary file from the host root filesystem as root, and place it inside the container:
```
templates:
/shadow:
when:
- star
OSV
Incus container image templating arbitrary host file read and write
osv·2026-01-22
CVE-2026-23954 [HIGH] Incus container image templating arbitrary host file read and write
Incus container image templating arbitrary host file read and write
### Summary
A user with the ability to launch a container with a custom image (e.g a member of the ‘incus’ group) can use directory traversal or symbolic links in the templating functionality to achieve host arbitrary file read, and host arbitrary file write, ultimately resulting in arbitrary command execution on the host. This can also be exploited in IncusOS.
### Details
When using an image with a `metadata.yaml` containing templates, both the source and target paths are not checked for symbolic links or directory traversal. [1] [2] For example, the following `metadata.yaml` snippet can read an arbitrary file from the host root filesystem as root, and place it inside the container:
```
templates:
/shadow:
when:
- star
OSV
CVE-2026-23954: Incus is a system container and virtual machine manager
osv·2026-01-22·CVSS 8.7
CVE-2026-23954 [HIGH] CVE-2026-23954: Incus is a system container and virtual machine manager
Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom image (e.g a member of the ‘incus’ group) to use directory traversal or symbolic links in the templating functionality to achieve host arbitrary file read, and host arbitrary file write. This ultimately results in arbitrary command execution on the host. When using an image with a metadata.yaml containing templates, both the source and target paths are not checked for symbolic links or directory traversal. This can also be exploited in IncusOS. A fix is planned for versions 6.0.6 and 6.21.0, but they have not been released at the time of publication.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-23954 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2026-23954 [HIGH] CVE-2026-23954 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23954 :
Homebrew vulnerability analysis and mitigation
Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom image (e.g a member of the ‘incus’ group) to use directory traversal or symbolic links in the templating functionality to achieve host arbitrary file read, and host arbitrary file write. This ultimately results in arbitrary command execution on the host. When using an image with a metadata.yaml containing templates, both the source and target paths are not checked for symbolic links or directory traversal. This can also be exploited in IncusOS. A fix is planned for versions 6.0.6 and 6.21.0, but they have not been released at the time of publication.
Source : NVD
## 8.7
Bugzilla
CVE-2026-23954 incus: container image templating arbitrary host file read and write [fedora-43]
bugzilla·2026-01-23·CVSS 8.7
CVE-2026-23954 [HIGH] CVE-2026-23954 incus: container image templating arbitrary host file read and write [fedora-43]
CVE-2026-23954 incus: container image templating arbitrary host file read and write [fedora-43]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-5af38b7ecb (incus-6.23-1.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-5af38b7ecb
---
FEDORA-2026-5af38b7ecb has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-5af38b7ecb`
You can provide feedback for this update here: https://bodhi.fedorapr
Bugzilla
CVE-2026-23954 incus: container image templating arbitrary host file read and write [fedora-42]
bugzilla·2026-01-23·CVSS 8.7
CVE-2026-23954 [HIGH] CVE-2026-23954 incus: container image templating arbitrary host file read and write [fedora-42]
CVE-2026-23954 incus: container image templating arbitrary host file read and write [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-a9017d0297 (incus-6.23-1.fc42) has been submitted as an update to Fedora 42.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-a9017d0297
---
FEDORA-2026-a9017d0297 has been pushed to the Fedora 42 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-a9017d0297`
You can provide feedback for this update here: https://bodhi.fedorapr
https://github.com/lxc/incus/blob/HEAD/internal/server/instance/drivers/driver_lxc.go#L7215https://github.com/lxc/incus/blob/HEAD/internal/server/instance/drivers/driver_lxc.go#L7294https://github.com/lxc/incus/security/advisories/GHSA-7f67-crqm-jgh7https://github.com/user-attachments/files/24473599/template_arbitrary_write.shhttps://github.com/user-attachments/files/24473601/templates_arbitrary_write.patch
2026-01-22
Published