PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-62313 lxc CVE debrief

The Incus system container and virtual machine manager, prior to version 7.3.0, has a vulnerability (CVE-2026-62313) where project-level enforcement of `restricted.containers.privilege=isolated` can be bypassed. This allows users to create non-isolated containers, sharing the host uid/gid map instead of receiving unique, non-overlapping ranges. This weakness in isolation boundary between co-tenant containers and the host can have significant operational impact. The vulnerability's source-confidence limits are based on the official CVE record and NVD details. A review of the official advisory is necessary for further context. Users should verify their deployments and plan for updates or mitigations through normal change control.

Vendor
lxc
Product
incus
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-21
Original CVE updated
2026-08-21
Advisory published
2026-08-21
Advisory updated
2026-08-21

Who should care

Users of Incus system container and virtual machine manager, especially those with multi-tenant environments, should be aware of this vulnerability and take steps to update and secure their deployments. Affected operators, platforms, and security teams should review the official advisory and plan for updates or mitigations through normal change control. Monitoring and detection should be reviewed for exposed assets that need extra review. Asset inventory and vulnerability management processes should be updated to reflect this vulnerability and track exceptions and retest remediated assets.

Technical summary

The Incus system container and virtual machine manager has a vulnerability (CVE-2026-62313) where project-level enforcement of restricted.containers.privilege=isolated can be bypassed, allowing creation of non-isolated containers. This issue is addressed in version 7.3.0. The vulnerability allows users to create containers that share the host uid/gid map instead of receiving unique, non-overlapping ranges, weakening the isolation boundary between co-tenant containers and the host.

Defensive priority

Users of Incus system container and virtual machine manager should prioritize updating to version 7.3.0 or later to address the identified vulnerability.

Recommended defensive actions

  • Review the official CVE record and NVD details to validate affected scope, severity, and vendor guidance.
  • Confirm whether affected Incus deployments exist in managed environments and assign an owner for follow-up.
  • Plan vendor-supported updates to version 7.3.0 or later through normal change control where exposure is confirmed.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Monitor container deployments for potential security risks related to CVE-2026-62313.

Evidence notes

The CVE record indicates that Incus versions prior to 7.3.0 are vulnerable to a security issue where project-level enforcement of restricted.containers.privilege=isolated can be bypassed. The NVD entry is currently limited, and further review of the official advisory is necessary to validate affected scope, severity, and vendor guidance. Users should verify their deployments and plan for updates or mitigations through normal change control. Compensating controls should be reviewed for exposed systems while remediation is scheduled and verified.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T15:16:45.867Z and has not been modified since then.