Incus has an arbitrary file write on its client due to trusted image hash
Published Aug 21, 2026
9.9
CRITICALCVSS 3.1
EPSS 0.73%
Description
Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary command execution as root on the server. Version 7.2.0 patches the issue.
Affected products
-
Affected
- < 7.2.0
No data.
No data.
No Red Hat product state for this CVE.
github.com/lxc/incus/v7/cmd/incusd
Go
Introduced 0 Fixed 7.2.0github.com/lxc/incus/v6
Go
Introduced 0 Fixed not fixedgithub.com/lxc/incus/v7
Go
Introduced 0 Fixed 7.2.0github.com/lxc/incus
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/lxc/incus/v7/cmd/incusd | 0 | 7.2.0 |
| Go | github.com/lxc/incus/v6 | 0 | not fixed |
| Go | github.com/lxc/incus/v7 | 0 | 7.2.0 |
| Go | github.com/lxc/incus | 0 | not fixed |
Remediation
Red Hat statement
Incus is not shipped in any Red Hat product. The community Fedora package is affected.
Red Hat mitigation
No mitigation is needed as Incus is not shipped in any Red Hat product.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-48769 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2521021 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-63983 Advisory
- https://github.com/advisories/GHSA-f6m5-xw2g-xc4x Advisory
- https://github.com/lxc/incus/security/advisories/GHSA-f6m5-xw2g-xc4x exploitx_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-48769
- https://www.cve.org/CVERecord?id=CVE-2026-48769
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-48769 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2521021 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-63983 | Advisory | |
| https://github.com/advisories/GHSA-f6m5-xw2g-xc4x | Advisory | |
| https://github.com/lxc/incus/security/advisories/GHSA-f6m5-xw2g-xc4x | exploitx_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-48769 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-48769 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub