cbcvebase.

Github.Com Lxc Incus V6 vulnerabilities

11 known vulnerabilities affecting github.com/lxc_incus_v6.

Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH3MEDIUM2LOW1UNKNOWN3

Vulnerabilities

Page 1 of 1
CVE-2026-33897P2CRITICAL≥ 0, < 6.23.02026-03-27
CVE-2026-33897 [CRITICAL] CWE-1336 Incus vulnerable to arbitrary file read and write through pongo templates Incus vulnerable to arbitrary file read and write through pongo templates ### Summary Instance template files can be used to cause arbitrary read or writes as root on the host server. ### Details Incus allows for pongo2 templates within instances which can be used at various times in the instance lifecycle to template files inside of the instance. This particular implementation of pongo
ghsaosv
CVE-2026-33945P2CRITICAL≥ 0, < 6.23.02026-03-27
CVE-2026-33945 [CRITICAL] CWE-22 Incus has an abitrary file write through its systemd-creds options Incus has an abitrary file write through its systemd-creds options ### Summary Incus instances have an option to provide credentials to systemd in the guest. For containers, this is handled through a shared directory. An attacker can use the name of a systemd credential to escape that directory and overwrite arbitrary files on the host system. This can in turn be used to perform local privilege
ghsaosv
CVE-2026-23954P3UNKNOWN≥ 6.1.02026-02-05
CVE-2026-23954 Incus container image templating arbitrary host file read and write in github.com/lxc/incus Incus container image templating arbitrary host file read and write in github.com/lxc/incus Incus container image templating arbitrary host file read and write in github.com/lxc/incus
osv
CVE-2026-23953P3HIGH≥ 0, < 6.21.02026-01-22
CVE-2026-23953 [HIGH] CWE-93 Incus container environment configuration newline injection Incus container environment configuration newline injection ### Summary A user with the ability to launch a container with a custom YAML configuration (e.g a member of the ‘incus’ group) can create an environment variable containing newlines, which can be used to add additional configuration items in the container’s `lxc.conf` due to the newline injection. This can allow adding arbitrary lifecycle hooks, ul
ghsaosv
CVE-2026-33898P3UNKNOWN≥ 0, < 6.23.02026-04-07
CVE-2026-33898 Local Incus UI web server vulnerable to nuthentication bypass in github.com/lxc/incus Local Incus UI web server vulnerable to nuthentication bypass in github.com/lxc/incus Local Incus UI web server vulnerable to nuthentication bypass in github.com/lxc/incus
osv
CVE-2026-33711P3MEDIUM≥ 0, < 6.23.02026-03-27
CVE-2026-33711 [MEDIUM] CWE-61 Incus vulnerable to local privilege escalation through VM screenshot path Incus vulnerable to local privilege escalation through VM screenshot path ### Summary Incus provides an API to retrieve VM screenshots, that API relies on the use of a temporary file for QEMU to write the screenshot to which is then picked up and sent to the user prior to deletion. As Incus uses predictable paths under /tmp for this, an attacker with local access to the system can abuse thi
ghsaosv
CVE-2025-64507P3HIGH≥ 0, < 6.19.02025-11-13
CVE-2025-64507 [HIGH] CWE-269 Incus vulnerable to local privilege escalation through custom storage volumes Incus vulnerable to local privilege escalation through custom storage volumes ### Impact This affects any Incus user in an environment where an unprivileged user may have root access to a container with an attached custom storage volume that has the `security.shifted` property set to `true` as well as access to the host as an unprivileged user. The most common case for this would be syst
ghsaosv
CVE-2026-33743P3MEDIUM≥ 0, < 6.23.02026-03-27
CVE-2026-33743 [MEDIUM] CWE-770 Incus vulnerable to denial of source through crafted bucket backup file Incus vulnerable to denial of source through crafted bucket backup file ### Summary A specially crafted storage bucket backup can be used by an user with access to Incus' storage bucket feature to crash the Incus daemon. Repeated use of this attack can be used to keep the server offline causing a denial of service of the control plane API. This does not impact any running workload, existing
ghsaosv
CVE-2025-52890P3HIGH≥ 6.12.0, < 6.14.02025-06-26
CVE-2025-52890 [HIGH] CWE-863 Incus creates nftables rules that partially bypass security options Incus creates nftables rules that partially bypass security options ### Summary When using an ACL on a device connected to a bridge, Incus generates nftables rules that partially bypass security options `security.mac_filtering`, `security.ipv4_filtering` and `security.ipv6_filtering`. This can lead to ARP spoofing on the bridge and to fully spoof another VM/container on the same bridge. ### Detai
ghsaosv
CVE-2026-33542P4UNKNOWN≥ 0, < 6.23.02026-04-07
CVE-2026-33542 Incus does not verify combined fingerprint when downloading images from simplestreams servers in github.com/lxc/incus Incus does not verify combined fingerprint when downloading images from simplestreams servers in github.com/lxc/incus Incus does not verify combined fingerprint when downloading images from simplestreams servers in github.com/lxc/incus
osv
CVE-2025-52889P4LOW≥ 0, < 6.14.02025-06-26
CVE-2025-52889 [LOW] CWE-770 Incus Allocation of Resources Without Limits allows firewall rule bypass on managed bridge networks Incus Allocation of Resources Without Limits allows firewall rule bypass on managed bridge networks ### Summary When using an ACL on a device connected to a bridge, Incus generates nftables rules for local services (DHCP, DNS...) that partially bypass security options `security.mac_filtering`, `security.ipv4_filtering` and `security.ipv6_filtering`. This can lead to
ghsaosv
Github.Com Lxc Incus V6 vulnerabilities | cvebase