PatchSiren

lxc CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL lxc CVE published 2026-08-21

CVE-2026-62940

Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluster member, user-supplied configuration overrides (including security-critical keys like `security.privileged` and `raw.lxc`) are applied without any project restriction enforcement, allowing a restricted project user to escalate to a privileged container and escape to the host. Versi [truncated]

CRITICAL lxc CVE published 2026-08-21

CVE-2026-62867

CVE-2026-62867 is a critical vulnerability in Incus, a system container and virtual machine manager. The vulnerability allows project-scoped users to inject arbitrary arguments into filesystem creation commands executed as root, potentially leading to privilege escalation and unauthorized access. This issue arises from improper validation of user-provided block.create_options in storage volume configurati [truncated]

MEDIUM lxc CVE published 2026-08-21

CVE-2026-62313

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T15:16:45.867Z and has not been modified since then. Incus is a system container and virtual machine manager. Prior to version 7.3.0, project-level enforcement of restricted.containers.privilege=isolated can be trivially bypassed, allowing a user to create a non-isolated (shared host idmap) contai [truncated]

HIGH lxc CVE published 2026-08-21

CVE-2026-55622

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name of an instance in that project can copy the instance to a new project. This issue could allow an attacker to access secrets in instances they are not authorized to access.

CRITICAL lxc CVE published 2026-08-21

CVE-2026-48769

CVE-2026-48769 is a critical vulnerability in Incus, a system container and virtual machine manager. A malicious image server can exploit an arbitrary file write issue in the Incus client by returning a crafted 'Incus-Image-Hash' header, potentially leading to arbitrary command execution as root on the server. The issue was patched in version 7.2.0.

LOW lxc CVE published 2026-08-21

CVE-2026-48756

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T15:16:41.210Z and has not been modified since then. This vulnerability affects Incus, a system container and virtual machine manager, where an authenticated user with can_create_storage_volumes permission can crash the incusd daemon by uploading a backup tarball with a missing volume_snapshots[*] [truncated]

CRITICAL lxc CVE published 2026-08-21

CVE-2026-48755

CVE-2026-48755 is a critical vulnerability in Incus, a system container and virtual machine manager. The vulnerability is caused by improper validation of user-provided backup compression algorithm, leading to argument injection in the constructed command line. This allows for arbitrary file writes on the host and potentially leads to arbitrary command execution. The issue was patched in version 7.1.0.

CRITICAL lxc CVE published 2026-08-21

CVE-2026-48753

Incus system container and virtual machine manager versions prior to 7.1.0 are vulnerable to path traversal via the S3 protocol upload endpoint, allowing creation of arbitrary files on the host, which could lead to arbitrary command execution. The issue is fixed in version 7.1.0. This vulnerability has a high impact on system administrators and security teams, as it can lead to potential command execution [truncated]

CRITICAL lxc CVE published 2026-08-21

CVE-2026-48750

The CVE-2026-48750 record indicates a critical vulnerability in Incus, a system container and virtual machine manager. The vulnerability exists in the `record-output` parameter of the `/instances/$name/exec` endpoint, which stores command output in the `exec-output` directory of the instance. If `exec-output` is a symlink, files can be written to an arbitrary location, allowing for arbitrary content in th [truncated]

CRITICAL lxc CVE published 2026-08-21

CVE-2026-48749

A specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution in Incus prior to version 7.2.0. This issue requires immediate attention from system administrators and security teams managing Incus installations, especially those with exposure to untrusted image sources. The vulnerability allows for potential arbitrary command exec [truncated]

MEDIUM lxc CVE published 2026-08-21

CVE-2026-47753

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T15:16:40.067Z and has not been modified since then. A nil-pointer dereference in Incus versions prior to 7.1.0 allows authenticated users with instance creation permissions to trigger a denial-of-service condition. This issue is a sibling of GHSA-fwj8-62r8-8p8m, GHSA-r7w7-mmxr-47r9, and GHSA-x5r6 [truncated]