Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-62867

Опубликовано: 21 авг. 2026
Источник: redhat
CVSS3: 9.9

Описание

Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided block.create_options in storage volume configuration leads to argument injection in the constructed filesystem creation command line. This allows a project-scoped user to inject arbitrary arguments into the binary executed as root. Version 7.3.0 patches the issue.

A flaw was found in Incus, a container and virtual machine manager. Improper validation of storage volume settings allows a project-scoped user to inject arguments into commands executed as root on the host.

Отчет

Incus is not shipped in any Red Hat product. The community Fedora package is affected.

Меры по смягчению последствий

No mitigation is needed as Incus is not shipped in any Red Hat product.

Дополнительная информация

Статус:

Critical
Дефект:
CWE-88
https://bugzilla.redhat.com/show_bug.cgi?id=2521014incus: Incus has an argument injection in storage volume block.create_options that leads to arbitrary command execution

9.9 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.9
ubuntu
14 дней назад

Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration leads to argument injection in the constructed filesystem creation command line. This allows a project-scoped user to inject arbitrary arguments into the binary executed as root. Version 7.3.0 patches the issue.

CVSS3: 9.9
nvd
14 дней назад

Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration leads to argument injection in the constructed filesystem creation command line. This allows a project-scoped user to inject arbitrary arguments into the binary executed as root. Version 7.3.0 patches the issue.

CVSS3: 9.9
debian
14 дней назад

Incus is a system container and virtual machine manager. Prior to vers ...

9.9 Critical

CVSS3