Описание
Incus has a restricted project bypass leading to arbitrary command execution
Summary
Instance snapshots ignore the restricted.containers.lowlevel=block setting; allowing for arbitrary command execution on the Incus server by abusing lowlevel hooks such as raw.lxc and raw.qemu.
Details
Instance snapshots ignore the restricted.containers.lowlevel=block setting; allowing for arbitrary command execution on the Incus server by abusing lowlevel hooks such as raw.lxc and raw.qemu.
As snapshots can be moved from one server to another, a malicious instance+snapshot can be crafted locally, moved to a restricted project and the snapshot restored for arbitrary command execution.
In practice, this allows a malicious actor to execute arbitrary commands on the host with root privileges.
PoC
Impact
- Bypass of project restrictions.
- Arbitrary command execution on the Incus server.
Пакеты
github.com/lxc/incus/v7/cmd/incusd
< 7.2.0
7.2.0