Incus out-of-bounds panic in snapshot metadata handling allows denial of service
Published May 6, 2026
7.1
HIGHCVSS 4.0
EPSS 0.47%
Description
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows an authenticated user with access to the storage volume feature to cause the Incus daemon to crash. The backup restore subsystem contains an out-of-bounds panic vulnerability caused by an invalid bounds check when indexing snapshot metadata arrays, and the same flawed pattern also appears in the migration path. When iterating through physical snapshots provided in a backup archive, the loop uses the index to look up corresponding metadata in the parsed `Config.Snapshots` and `Config.VolumeSnapshots` slices. The guard condition `len(slice) >= i-1` is incorrect because it can still evaluate to true when the subsequent slice[i] access is out of bounds.
An attacker can submit a backup archive that contains physical snapshot directories while supplying a tampered `index.yaml` with an empty or truncated snapshot metadata array, causing the daemon to index beyond the end of the metadata slice and crash. Repeated use of this issue can be used to keep Incus offline, causing a denial of service. This issue is fixed in version 7.0.0.
Affected products
-
- Version < 7.0.0StatusaffectedConstraints-
- Version
- < 7.0.0
No data.
No Red Hat product state for this CVE.
github.com/lxc/incus/v6/cmd/incusd
Go
Introduced 0 Fixed 7.0.0github.com/lxc/incus/v7
Go
Introduced 0 Fixed 7.0.0github.com/lxc/incus
Go
Introduced 0 Fixed not fixedgithub.com/lxc/incus/v6
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/lxc/incus/v6/cmd/incusd | 0 | 7.0.0 |
| Go | github.com/lxc/incus/v7 | 0 | 7.0.0 |
| Go | github.com/lxc/incus | 0 | not fixed |
| Go | github.com/lxc/incus/v6 | 0 | not fixed |
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed May 7, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
May–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.47% (0.00471) | 38.40th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.41% (0.00408) | 32.29th | v5 (v2026.06.15) |
| May 7, 2026 | 0.04% (0.00042) | 12.57th | v4 (v2025.03.14) |
References (4)
- https://github.com/advisories/GHSA-4m88-wxj4-9qj6 Advisory
- https://github.com/lxc/incus/blob/v6.22.0/internal/server/storage/backend.go x_refsource_MISCProduct
- https://github.com/lxc/incus/security/advisories/GHSA-4m88-wxj4-9qj6 exploitx_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-40251
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-4m88-wxj4-9qj6 | Advisory | |
| https://github.com/lxc/incus/blob/v6.22.0/internal/server/storage/backend.go | x_refsource_MISCProduct | |
| https://github.com/lxc/incus/security/advisories/GHSA-4m88-wxj4-9qj6 | exploitx_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-40251 |
Change history (0)
No recorded changes yet.