Описание
Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided block.create_options in storage volume configuration leads to argument injection in the constructed filesystem creation command line. This allows a project-scoped user to inject arbitrary arguments into the binary executed as root. Version 7.3.0 patches the issue.
A flaw was found in Incus, a container and virtual machine manager. Improper validation of storage volume settings allows a project-scoped user to inject arguments into commands executed as root on the host.
Отчет
Incus is not shipped in any Red Hat product. The community Fedora package is affected.
Меры по смягчению последствий
No mitigation is needed as Incus is not shipped in any Red Hat product.
Дополнительная информация
Статус:
9.9 Critical
CVSS3
Связанные уязвимости
Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration leads to argument injection in the constructed filesystem creation command line. This allows a project-scoped user to inject arbitrary arguments into the binary executed as root. Version 7.3.0 patches the issue.
Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration leads to argument injection in the constructed filesystem creation command line. This allows a project-scoped user to inject arbitrary arguments into the binary executed as root. Version 7.3.0 patches the issue.
Incus is a system container and virtual machine manager. Prior to vers ...
9.9 Critical
CVSS3