Information on source package incus

Available versions

ReleaseVersion
trixie6.0.4-2+deb13u8
trixie (security)6.0.4-2+deb13u9
forky7.0.1-2
sid7.0.1-3

Open issues

BugtrixieforkysidDescription
CVE-2026-81501vulnerable (no DSA)vulnerablefixed
CVE-2026-81500vulnerable (no DSA)vulnerablefixed

Open unimportant issues

BugtrixieforkysidDescription
CVE-2026-33898vulnerablefixedfixedIncus is a system container and virtual machine manager. Prior to vers ...
CVE-2026-33711vulnerablefixedfixedIncus is a system container and virtual machine manager. Incus provide ...

Resolved issues

BugDescription
CVE-2026-81499GHSA-6v6x-387m-rj4w: Project restriction bypass on network address sets
CVE-2026-81498GHSA-m3j6-p3v3-qmjv: Container configuration newline injection through nvidia.driver.capabilities
CVE-2026-81497GHSA-4qxq-p5hm-3q3p: Arbitrary host file read+write via VM template path traversal
CVE-2026-81496GHSA-26gp-p5fw-3r2h: Arbitrary file write on host via path traversal in instance backup import
CVE-2026-81495GHSA-67qw-68v3-36h6: Arbitrary file write on host via path traversal in custom volume import
CVE-2026-81494GHSA-7fj9-65v4-rp7h: Arbitrary file write on host via image-planted symlinks and oci.dns.* newline injection
CVE-2026-81493GHSA-p2v3-6wvc-cv3p: Arbitrary file write on host via image fingerprint path traversal
CVE-2026-63343Incus is a system container and virtual machine manager. Prior to vers ...
CVE-2026-63125Incus is a system container and virtual machine manager. Prior to vers ...
CVE-2026-62941Incus is a system container and virtual machine manager. Prior to vers ...
CVE-2026-62940Incus is a system container and virtual machine manager. Prior to vers ...
CVE-2026-62867Incus is a system container and virtual machine manager. Prior to vers ...
CVE-2026-62313Incus is a system container and virtual machine manager. Prior to vers ...
CVE-2026-55622Incus is a system container and virtual machine manager. Prior to vers ...
CVE-2026-55621Incus is a system container and virtual machine manager. Prior to vers ...
CVE-2026-48769Incus is a system container and virtual machine manager. Prior to vers ...
CVE-2026-48756Incus is a system container and virtual machine manager. Prior to vers ...
CVE-2026-48755Incus is a system container and virtual machine manager. Prior to vers ...
CVE-2026-48754Incus is a system container and virtual machine manager. Prior to vers ...
CVE-2026-48753Incus is a system container and virtual machine manager. Prior to vers ...
CVE-2026-48752Incus is a system container and virtual machine manager. Prior to vers ...
CVE-2026-48751Incus is a system container and virtual machine manager. Prior to vers ...
CVE-2026-48750Incus is a system container and virtual machine manager. Prior to vers ...
CVE-2026-48749Incus is a system container and virtual machine manager. Prior to vers ...
CVE-2026-47753Incus is a system container and virtual machine manager. Prior to vers ...
CVE-2026-41685Incus is a system container and virtual machine manager. Prior to vers ...
CVE-2026-41684Incus is a system container and virtual machine manager. Prior to vers ...
CVE-2026-41648Incus is a system container and virtual machine manager. Prior to vers ...
CVE-2026-41647Incus is a system container and virtual machine manager. Prior to vers ...
CVE-2026-40251Incus is a system container and virtual machine manager. In versions b ...
CVE-2026-40243Incus is a system container and virtual machine manager. In versions b ...
CVE-2026-40197Incus is a system container and virtual machine manager. In versions b ...
CVE-2026-40195Incus is a system container and virtual machine manager. In versions b ...
CVE-2026-35527Incus is an open source container and virtual machine manager. In vers ...
CVE-2026-34179In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate fu ...
CVE-2026-34178In Canonical LXD before 6.8, the backup import path validates project ...
CVE-2026-34177Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist ...
CVE-2026-33945Incus is a system container and virtual machine manager. Incus instanc ...
CVE-2026-33897Incus is a system container and virtual machine manager. Prior to vers ...
CVE-2026-33743Incus is a system container and virtual machine manager. Prior to vers ...
CVE-2026-33542Incus is a system container and virtual machine manager. Prior to vers ...
CVE-2026-28384An improper sanitization of the compression_algorithm parameter in Can ...
CVE-2026-23954Incus is a system container and virtual machine manager. Versions 6.21 ...
CVE-2026-23953Incus is a system container and virtual machine manager. In versions 6 ...
CVE-2026-3351Improper authorization in the API endpoint GET /1.0/certificates in Ca ...
CVE-2025-64507Incus is a system container and virtual machine manager. An issue in v ...
CVE-2025-54293Path Traversal in the log file retrieval function in Canonical LXD 5.0 ...
CVE-2025-54291Information disclosure in images API in Canonical LXD before 6.5 and 5 ...
CVE-2025-54290Information disclosure in image export API in Canonical LXD before 6.5 ...
CVE-2025-54289Privilege Escalation in operations API in Canonical LXD <6.5 on multip ...
CVE-2025-54288Information Spoofing in devLXD Server in Canonical LXD versions 4.0 an ...
CVE-2025-54287Template Injection in instance snapshot creation component in Canonica ...
CVE-2025-54286Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions ...
CVE-2025-52890Incus is a system container and virtual machine manager. When using an ...
CVE-2025-52889Incus is a system container and virtual machine manager. When using an ...
CVE-2024-6219Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a ...
CVE-2024-6156Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could ...
CVE-2023-49721An insecure default to allow UEFI Shell in EDK2 was left enabled in LX ...

Security announcements

DSA / DLADescription
DSA-6407-1incus - security update
DSA-6370-1incus - security update
DSA-6244-1incus - security update
DSA-6212-1incus - security update
DSA-6184-1incus - security update
DSA-6109-1incus - security update
DSA-6051-1incus - security update
DSA-6027-1incus - security update

Search for package or bug name: Reporting problems