CVE-2026-33711

EUVD-2026-16462
Incus is a system container and virtual machine manager. Incus provides an API to retrieve VM screenshots. That API relies on the use of a temporary file for QEMU to write the screenshot to which is then picked up and sent to the user prior to deletion. As versions prior to 6.23.0 use predictable paths under /tmp for this, an attacker with local access to the system can abuse this mechanism by creating their own symlinks ahead of time. On the vast majority of Linux systems, this will result in a "Permission denied" error when requesting a screenshot. That's because the Linux kernel has a security feature designed to block such attacks, `protected_symlinks`. On the rare systems with this purposefully disabled, it's then possible to trick Incus intro truncating and altering the mode and permissions of arbitrary files on the filesystem, leading to a potential denial of service or possible local privilege escalation. Version 6.23.0 fixes the issue.
Symlink
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 27.68%
Affected Products (NVD)
VendorProductVersion
linuxcontainersincus
𝑥
< 6.23.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
incus
forky
7.0.1-2
fixed
sid
7.0.1-2
fixed
trixie
unimportant
trixie (security)
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
incus
jammy
dne
noble
needs-triage
questing
ignored
resolute
needs-triage
lxd
bionic
not-affected
focal
not-affected
jammy
dne
noble
dne
questing
dne
resolute
dne
xenial
not-affected