Back

CRITICAL

Incus has an arbitrary file write on its client due to trusted image hash

Published Aug 21, 2026

Description

Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary command execution as root on the server. Version 7.2.0 patches the issue.

Affected products

Remediation

Red Hat statement

Incus is not shipped in any Red Hat product. The community Fedora package is affected.

Red Hat mitigation

No mitigation is needed as Incus is not shipped in any Red Hat product.

References (7)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Aug 21, 2026
Updated Aug 21, 2026
Reserved May 22, 2026

CISA Vulnrichment

Updated Aug 21, 2026

NVD

Status Deferred
Modified Sep 18, 2026

Red Hat

Severity Critical
Public date Aug 21, 2026
Bugzilla 2521021

ENISA EUVD

Assigner GitHub_M
Published Aug 21, 2026
Updated Aug 21, 2026