Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6407-1 | incus security update |
Fri, 21 Aug 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lxc
Lxc incus |
|
| Vendors & Products |
Lxc
Lxc incus |
Fri, 21 Aug 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and `can_create_instances`) can execute arbitrary code as root on the host. A crafted image ships `backup.yaml` as a symlink to a host file. When the root daemon writes the instance's backup file, it follows the symlink. Version 7.3.0 patches the issue. | |
| Title | Incus vulnerable to root RCE via image backup.yaml symlink | |
| Weaknesses | CWE-59 CWE-61 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-21T15:02:55.718Z
Reserved: 2026-07-15T16:54:55.816Z
Link: CVE-2026-63125
No data.
Status : Received
Published: 2026-08-21T15:16:46.427
Modified: 2026-08-21T15:16:46.427
Link: CVE-2026-63125
No data.
OpenCVE Enrichment
Updated: 2026-08-21T17:30:03Z
Debian DSA