CVE-2026-48755

EUVD-2026-63982
Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary file write on the host, possibly leading to arbitrary command execution. Version 7.1.0 patches the issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.9 CRITICAL
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Debian logo
Debian Releases
Debian Product
Codename
incus
forky
7.0.1-2
fixed
sid
7.0.1-2
fixed
trixie
6.0.4-2+deb13u8
fixed
trixie (security)
6.0.4-2+deb13u9
fixed
lxd
bookworm
vulnerable
bookworm (security)
vulnerable
trixie
5.0.2+git20231211.1364ae4-9+deb13u7
fixed
trixie (security)
5.0.2+git20231211.1364ae4-9+deb13u7
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
incus
jammy
dne
noble
needs-triage
questing
ignored
resolute
needs-triage
lxd
bionic
needs-triage
focal
needs-triage
jammy
dne
noble
dne
questing
dne
resolute
dne
xenial
needs-triage