Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-33542

Опубликовано: 26 мар. 2026
Источник: nvd
CVSS3: 4.8
EPSS Низкий

Описание

Incus is a system container and virtual machine manager. Prior to version 6.23.0, a lack of validation of the image fingerprint when downloading from simplestreams image servers opens the door to image cache poisoning and under very narrow circumstances exposes other tenants to running attacker controlled images rather than the expected one. Version 6.23.0 patches the issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:linuxcontainers:incus:*:*:*:*:*:*:*:*
Версия до 6.23.0 (исключая)

EPSS

Процентиль: 8%
0.0018
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 4.8
ubuntu
4 месяца назад

Incus is a system container and virtual machine manager. Prior to version 6.23.0, a lack of validation of the image fingerprint when downloading from simplestreams image servers opens the door to image cache poisoning and under very narrow circumstances exposes other tenants to running attacker controlled images rather than the expected one. Version 6.23.0 patches the issue.

CVSS3: 8.5
redhat
4 месяца назад

Incus is a system container and virtual machine manager. Prior to version 6.23.0, a lack of validation of the image fingerprint when downloading from simplestreams image servers opens the door to image cache poisoning and under very narrow circumstances exposes other tenants to running attacker controlled images rather than the expected one. Version 6.23.0 patches the issue.

msrc
4 месяца назад

Incus does not verify combined fingerprint when downloading images from simplestreams servers

CVSS3: 4.8
debian
4 месяца назад

Incus is a system container and virtual machine manager. Prior to vers ...

github
4 месяца назад

Incus does not verify combined fingerprint when downloading images from simplestreams servers

EPSS

Процентиль: 8%
0.0018
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-295