Information on source package incus

Available versions

ReleaseVersion
trixie6.0.4-2+deb13u4
trixie (security)6.0.4-2+deb13u6
forky6.0.6-3
sid6.0.6-3

Open unimportant issues

BugtrixieforkysidDescription
CVE-2026-33898vulnerablevulnerablevulnerableIncus is a system container and virtual machine manager. Prior to vers ...
CVE-2026-33711vulnerablefixedfixedIncus is a system container and virtual machine manager. Incus provide ...

Resolved issues

BugDescription
CVE-2026-34179In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate fu ...
CVE-2026-34178In Canonical LXD before 6.8, the backup import path validates project ...
CVE-2026-34177Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist ...
CVE-2026-33945Incus is a system container and virtual machine manager. Incus instanc ...
CVE-2026-33897Incus is a system container and virtual machine manager. Prior to vers ...
CVE-2026-33743Incus is a system container and virtual machine manager. Prior to vers ...
CVE-2026-33542Incus is a system container and virtual machine manager. Prior to vers ...
CVE-2026-28384An improper sanitization of the compression_algorithm parameter in Can ...
CVE-2026-23954Incus is a system container and virtual machine manager. Versions 6.21 ...
CVE-2026-23953Incus is a system container and virtual machine manager. In versions 6 ...
CVE-2026-3351Improper authorization in the API endpoint GET /1.0/certificates in Ca ...
CVE-2025-64507Incus is a system container and virtual machine manager. An issue in v ...
CVE-2025-54293Path Traversal in the log file retrieval function in Canonical LXD 5.0 ...
CVE-2025-54291Information disclosure in images API in Canonical LXD before 6.5 and 5 ...
CVE-2025-54290Information disclosure in image export API in Canonical LXD before 6.5 ...
CVE-2025-54289Privilege Escalation in operations API in Canonical LXD <6.5 on multip ...
CVE-2025-54288Information Spoofing in devLXD Server in Canonical LXD versions 4.0 an ...
CVE-2025-54287Template Injection in instance snapshot creation component in Canonica ...
CVE-2025-54286Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions ...
CVE-2025-52890Incus is a system container and virtual machine manager. When using an ...
CVE-2025-52889Incus is a system container and virtual machine manager. When using an ...
CVE-2024-6219Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a ...
CVE-2024-6156Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could ...
CVE-2023-49721An insecure default to allow UEFI Shell in EDK2 was left enabled in LX ...

Security announcements

DSA / DLADescription
DSA-6212-1incus - security update
DSA-6184-1incus - security update
DSA-6109-1incus - security update
DSA-6051-1incus - security update
DSA-6027-1incus - security update

Search for package or bug name: Reporting problems