TEMP-0000000-A1BB32

NameTEMP-0000000-A1BB32
DescriptionGHSA-67qw-68v3-36h6: Arbitrary file write on host via path traversal in custom volume import
SourceAutomatically generated temporary name. Not for external reference.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
incus (PTS)trixie (security), trixie6.0.4-2+deb13u8vulnerable
forky7.0.1-1vulnerable
sid7.0.1-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
incussource(unstable)7.0.1-2

Notes

https://github.com/lxc/incus/security/advisories/GHSA-67qw-68v3-36h6
https://github.com/lxc/incus/pull/3750

Search for package or bug name: Reporting problems