CVE-2026-33743
published 2026-03-26CVE-2026-33743: Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket backup can be used by an user with access…
PriorityP338medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.39%
31.1th percentile
Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket backup can be used by an user with access to Incus' storage bucket feature to crash the Incus daemon. Repeated use of this attack can be used to keep the server offline causing a denial of service of the control plane API. This does not impact any running workload, existing containers and virtual machines will keep operating. Version 6.23.0 fixes the issue.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | incus | < incus 6.0.6-2 (forky) | incus 6.0.6-2 (forky) |
| debian | lxd | < incus 6.0.6-2 (forky) | incus 6.0.6-2 (forky) |
| github.com | lxc_incus | 0 – 0.7.0 | — |
| github.com | lxc_incus_v6 | >= 0 < 6.23.0 | 6.23.0 |
| linuxcontainers | incus | < 6.23.0 | 6.23.0 |
| lxc | incus | < 6.23.0 | 6.23.0 |
| lxc | incus | >= 0 < 6.0.4-2+deb13u5 | 6.0.4-2+deb13u5 |
| lxc | incus | >= 0 < 6.0.6-2 | 6.0.6-2 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Incus vulnerable to denial of source through crafted bucket backup file in github.com/lxc/incus
osv·2026-04-07
CVE-2026-33743 Incus vulnerable to denial of source through crafted bucket backup file in github.com/lxc/incus
Incus vulnerable to denial of source through crafted bucket backup file in github.com/lxc/incus
Incus vulnerable to denial of source through crafted bucket backup file in github.com/lxc/incus
GHSA
Incus vulnerable to denial of source through crafted bucket backup file
ghsa·2026-03-27
CVE-2026-33743 [MEDIUM] CWE-770 Incus vulnerable to denial of source through crafted bucket backup file
Incus vulnerable to denial of source through crafted bucket backup file
### Summary
A specially crafted storage bucket backup can be used by an user with access to Incus' storage bucket feature to crash the Incus daemon. Repeated use of this attack can be used to keep the server offline causing a denial of service of the control plane API.
This does not impact any running workload, existing containers and virtual machines will keep operating.
### Details
The S3 transfer manager contains an unchecked string slicing vulnerability that allows an authenticated attacker to crash the daemon during S3 restore operations. While processing tar headers from a supplied backup archive, the code skips only the index entry and strips the expected bucket prefix from all other entries without first va
OSV
Incus vulnerable to denial of source through crafted bucket backup file
osv·2026-03-27
CVE-2026-33743 [MEDIUM] Incus vulnerable to denial of source through crafted bucket backup file
Incus vulnerable to denial of source through crafted bucket backup file
### Summary
A specially crafted storage bucket backup can be used by an user with access to Incus' storage bucket feature to crash the Incus daemon. Repeated use of this attack can be used to keep the server offline causing a denial of service of the control plane API.
This does not impact any running workload, existing containers and virtual machines will keep operating.
### Details
The S3 transfer manager contains an unchecked string slicing vulnerability that allows an authenticated attacker to crash the daemon during S3 restore operations. While processing tar headers from a supplied backup archive, the code skips only the index entry and strips the expected bucket prefix from all other entries without first va
OSV
CVE-2026-33743: Incus is a system container and virtual machine manager
osv·2026-03-26·CVSS 6.5
CVE-2026-33743 [MEDIUM] CVE-2026-33743: Incus is a system container and virtual machine manager
Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket backup can be used by an user with access to Incus' storage bucket feature to crash the Incus daemon. Repeated use of this attack can be used to keep the server offline causing a denial of service of the control plane API. This does not impact any running workload, existing containers and virtual machines will keep operating. Version 6.23.0 fixes the issue.
Red Hat
incus: Incus: Denial of Service via specially crafted storage bucket backup
vendor_redhat·2026-03-26·CVSS 6.5
CVE-2026-33743 [MEDIUM] CWE-1286 incus: Incus: Denial of Service via specially crafted storage bucket backup
incus: Incus: Denial of Service via specially crafted storage bucket backup
Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket backup can be used by an user with access to Incus' storage bucket feature to crash the Incus daemon. Repeated use of this attack can be used to keep the server offline causing a denial of service of the control plane API. This does not impact any running workload, existing containers and virtual machines will keep operating. Version 6.23.0 fixes the issue.
A flaw was found in Incus, a system container and virtual machine manager. A user with access to Incus' storage bucket feature can exploit this vulnerability by using a specially crafted storage bucket backup. This can cause the Incus daemon to
Debian
CVE-2026-33743: incus - Incus is a system container and virtual machine manager. Prior to version 6.23.0...
vendor_debian·2026·CVSS 6.5
CVE-2026-33743 [MEDIUM] CVE-2026-33743: incus - Incus is a system container and virtual machine manager. Prior to version 6.23.0...
Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket backup can be used by an user with access to Incus' storage bucket feature to crash the Incus daemon. Repeated use of this attack can be used to keep the server offline causing a denial of service of the control plane API. This does not impact any running workload, existing containers and virtual machines will keep operating. Version 6.23.0 fixes the issue.
Scope: local
forky: resolved (fixed in 6.0.6-2)
sid: resolved (fixed in 6.0.6-2)
trixie: resolved (fixed in 6.0.4-2+deb13u5)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-33743 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-33743 [MEDIUM] CVE-2026-33743 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33743 :
Homebrew vulnerability analysis and mitigation
Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket backup can be used by an user with access to Incus' storage bucket feature to crash the Incus daemon. Repeated use of this attack can be used to keep the server offline causing a denial of service of the control plane API. This does not impact any running workload, existing containers and virtual machines will keep operating. Version 6.23.0 fixes the issue.
Source : NVD
## 6.5
Score
Published March 26, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
Homebrew
Linux Debian
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Proba
Bugzilla
CVE-2026-33743 incus: Incus: Denial of Service via specially crafted storage bucket backup [fedora-42]
bugzilla·2026-03-26·CVSS 6.5
CVE-2026-33743 [MEDIUM] CVE-2026-33743 incus: Incus: Denial of Service via specially crafted storage bucket backup [fedora-42]
CVE-2026-33743 incus: Incus: Denial of Service via specially crafted storage bucket backup [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-a9017d0297 (incus-6.23-1.fc42) has been submitted as an update to Fedora 42.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-a9017d0297
---
FEDORA-2026-a9017d0297 has been pushed to the Fedora 42 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-a9017d0297`
You can provide feedback for this update here: https://bodhi.f
Bugzilla
CVE-2026-33743 incus: Incus: Denial of Service via specially crafted storage bucket backup [fedora-43]
bugzilla·2026-03-26·CVSS 6.5
CVE-2026-33743 [MEDIUM] CVE-2026-33743 incus: Incus: Denial of Service via specially crafted storage bucket backup [fedora-43]
CVE-2026-33743 incus: Incus: Denial of Service via specially crafted storage bucket backup [fedora-43]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-5af38b7ecb (incus-6.23-1.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-5af38b7ecb
---
FEDORA-2026-5af38b7ecb has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-5af38b7ecb`
You can provide feedback for this update here: https://bodhi.f
2026-03-26
Published