Incus: Nil-pointer dereference in createDependentVolumesFromBackup on disk.{Volume,VolumeSnapshots,Pool}
Published Aug 21, 2026
2.1
LOWCVSS 4.0
EPSS 0.38%
Description
Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).createDependentVolumesFromBackup` in `internal/server/storage/backend.go` contains a cluster of unguarded pointer derefs on every dependent-volume entry's `VolumeSnapshots[i]`, `Volume`, and `Pool` sub-fields. An authenticated user with `can_create_instances` permission on any project can crash the `incusd` daemon by uploading an instance backup tarball whose `dependent_volumes[*]` block contains a nil snapshot pointer (or omits `volume:` / `pool:`). This is a sibling-field variant of the 2026-05-04 batch fix `d768f81c0a1d985f35ae56219519822b080bf5e3` ("Properly check dependent volumes on import"). That commit added `if disk == nil` at the top of the outer loop, but did not guard the four sub-pointer fields the loop body dereferences naked. Version 7.1.0 contains an updated patch.
Affected products
-
- Version < 7.1.0StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
github.com/lxc/incus/v7/cmd/incusd
Go
Introduced 0 Fixed 7.1.0github.com/lxc/incus
Go
Introduced 0 Fixed not fixedgithub.com/lxc/incus/v6
Go
Introduced 0 Fixed not fixedgithub.com/lxc/incus/v7
Go
Introduced 0 Fixed 7.1.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/lxc/incus/v7/cmd/incusd | 0 | 7.1.0 |
| Go | github.com/lxc/incus | 0 | not fixed |
| Go | github.com/lxc/incus/v6 | 0 | not fixed |
| Go | github.com/lxc/incus/v7 | 0 | 7.1.0 |
Remediation
No remediation recorded yet.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-63981 Advisory
- https://github.com/advisories/GHSA-4xg6-52mh-fpw8 Advisory
- https://github.com/lxc/incus/security/advisories/GHSA-4xg6-52mh-fpw8 exploitx_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-63981 | Advisory | |
| https://github.com/advisories/GHSA-4xg6-52mh-fpw8 | Advisory | |
| https://github.com/lxc/incus/security/advisories/GHSA-4xg6-52mh-fpw8 | exploitx_refsource_CONFIRM |
Change history (0)
No recorded changes yet.