Security: lxc/incus
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Project restriction bypass on network address setsGHSA-6v6x-387m-rj4w published
Jul 30, 2026 by stgraberModerate -
Arbitrary file write on host via path traversal in custom volume importGHSA-67qw-68v3-36h6 published
Jul 30, 2026 by stgraberCritical -
Arbitrary file write on host via path traversal in instance backup importGHSA-26gp-p5fw-3r2h published
Jul 30, 2026 by stgraberCritical -
Arbitrary file write on host via image-planted symlinks and oci.dns.* newline injectionGHSA-7fj9-65v4-rp7h published
Jul 30, 2026 by stgraberCritical -
Arbitrary host file read+write via VM template path traversal (incomplete fix of CVE-2026-48752)GHSA-4qxq-p5hm-3q3p published
Jul 30, 2026 by stgraberHigh -
Arbitrary file write on host via image fingerprint path traversal (incomplete fix of CVE-2026-48769)GHSA-p2v3-6wvc-cv3p published
Jul 30, 2026 by stgraberCritical -
Arbitrary file read+write on host via metadata.yaml symlink in crafted imageGHSA-fmjx-5j3g-997p published
Jul 30, 2026 by stgraberCritical -
Arbitrary file write on host via backup.yaml symlink in crafted imageGHSA-6rqx-22hc-qm36 published
Jul 30, 2026 by stgraberCritical -
Container configuration newline injection through nvidia.driver.capabilitiesGHSA-m3j6-p3v3-qmjv published
Jul 30, 2026 by stgraberHigh -
Project restriction bypass via cross-project instance copyGHSA-mq9x-prm8-3vpw published
Jul 30, 2026 by stgraberCritical