Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33542

Опубликовано: 26 мар. 2026
Источник: redhat
CVSS3: 8.5
EPSS Низкий

Описание

Incus is a system container and virtual machine manager. Prior to version 6.23.0, a lack of validation of the image fingerprint when downloading from simplestreams image servers opens the door to image cache poisoning and under very narrow circumstances exposes other tenants to running attacker controlled images rather than the expected one. Version 6.23.0 patches the issue.

A flaw was found in Incus, a system container and virtual machine manager. A remote attacker could exploit a lack of validation of image fingerprints when downloading from simplestreams image servers. This vulnerability, under specific conditions, could lead to image cache poisoning, allowing an attacker to expose other tenants to running their controlled images instead of the expected ones.

Отчет

This Important vulnerability in Incus, a system container and virtual machine manager, stems from insufficient image fingerprint validation during downloads from simplestreams image servers. Under specific conditions, this could lead to image cache poisoning, allowing an attacker to expose other tenants to running controlled images. This issue primarily affects community projects such as Fedora.

Дополнительная информация

Статус:

Important
Дефект:
CWE-354
https://bugzilla.redhat.com/show_bug.cgi?id=2452019github.com/lxc/incus: Incus: Image cache poisoning due to insufficient image fingerprint validation

EPSS

Процентиль: 8%
0.0018
Низкий

8.5 High

CVSS3

Связанные уязвимости

CVSS3: 4.8
ubuntu
4 месяца назад

Incus is a system container and virtual machine manager. Prior to version 6.23.0, a lack of validation of the image fingerprint when downloading from simplestreams image servers opens the door to image cache poisoning and under very narrow circumstances exposes other tenants to running attacker controlled images rather than the expected one. Version 6.23.0 patches the issue.

CVSS3: 4.8
nvd
4 месяца назад

Incus is a system container and virtual machine manager. Prior to version 6.23.0, a lack of validation of the image fingerprint when downloading from simplestreams image servers opens the door to image cache poisoning and under very narrow circumstances exposes other tenants to running attacker controlled images rather than the expected one. Version 6.23.0 patches the issue.

msrc
4 месяца назад

Incus does not verify combined fingerprint when downloading images from simplestreams servers

CVSS3: 4.8
debian
4 месяца назад

Incus is a system container and virtual machine manager. Prior to vers ...

github
4 месяца назад

Incus does not verify combined fingerprint when downloading images from simplestreams servers

EPSS

Процентиль: 8%
0.0018
Низкий

8.5 High

CVSS3