TEMP-0000000-FEDD3E

NameTEMP-0000000-FEDD3E
DescriptionGHSA-p2v3-6wvc-cv3p: Arbitrary file write on host via image fingerprint path traversal
SourceAutomatically generated temporary name. Not for external reference.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
incus (PTS)trixie6.0.4-2+deb13u8vulnerable
trixie (security)6.0.4-2+deb13u9fixed
forky, sid7.0.1-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
incussourcetrixie6.0.4-2+deb13u9
incussource(unstable)7.0.1-2

Notes

https://github.com/lxc/incus/security/advisories/GHSA-p2v3-6wvc-cv3p
https://github.com/lxc/incus/pull/3750

Search for package or bug name: Reporting problems