Логотип exploitDog
bind: "CVE-2025-64507"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2025-64507"

Количество 6

Количество 6

ubuntu логотип

CVE-2025-64507

2 месяца назад

Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.19.0 affects any Incus user in an environment where an unprivileged user may have root access to a container with an attached custom storage volume that has the `security.shifted` property set to `true` as well as access to the host as an unprivileged user. The most common case for this would be systems using `incus-user` with the less privileged `incus` group to provide unprivileged users with an isolated restricted access to Incus. Such users may be able to create a custom storage volume with the necessary property (depending on kernel and filesystem support) and can then write a setuid binary from within the container which can be executed as an unprivileged user on the host to gain root privileges. A patch for this issue is expected in versions 6.0.6 and 6.19.0. As a workaround, permissions can be manually restricted until a patched version of Incus is deployed.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2025-64507

2 месяца назад

Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.19.0 affects any Incus user in an environment where an unprivileged user may have root access to a container with an attached custom storage volume that has the `security.shifted` property set to `true` as well as access to the host as an unprivileged user. The most common case for this would be systems using `incus-user` with the less privileged `incus` group to provide unprivileged users with an isolated restricted access to Incus. Such users may be able to create a custom storage volume with the necessary property (depending on kernel and filesystem support) and can then write a setuid binary from within the container which can be executed as an unprivileged user on the host to gain root privileges. A patch for this issue is expected in versions 6.0.6 and 6.19.0. As a workaround, permissions can be manually restricted until a patched version of Incus is deployed.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2025-64507

2 месяца назад

Incus is a system container and virtual machine manager. An issue in v ...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-56mx-8g9f-5crf

2 месяца назад

Incus vulnerable to local privilege escalation through custom storage volumes

EPSS: Низкий
fstec логотип

BDU:2025-16114

2 месяца назад

Уязвимость системы управления контейнерами и менеджера виртуальных машин Incus, связанная с небезопасным управлением привилегиями, позволяющая нарушителю повысить свои привилегии

CVSS3: 8.4
EPSS: Низкий
redos логотип

ROS-20251216-7352

около 1 месяца назад

Уязвимость incus

CVSS3: 8.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-64507

Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.19.0 affects any Incus user in an environment where an unprivileged user may have root access to a container with an attached custom storage volume that has the `security.shifted` property set to `true` as well as access to the host as an unprivileged user. The most common case for this would be systems using `incus-user` with the less privileged `incus` group to provide unprivileged users with an isolated restricted access to Incus. Such users may be able to create a custom storage volume with the necessary property (depending on kernel and filesystem support) and can then write a setuid binary from within the container which can be executed as an unprivileged user on the host to gain root privileges. A patch for this issue is expected in versions 6.0.6 and 6.19.0. As a workaround, permissions can be manually restricted until a patched version of Incus is deployed.

CVSS3: 7.8
0%
Низкий
2 месяца назад
nvd логотип
CVE-2025-64507

Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.19.0 affects any Incus user in an environment where an unprivileged user may have root access to a container with an attached custom storage volume that has the `security.shifted` property set to `true` as well as access to the host as an unprivileged user. The most common case for this would be systems using `incus-user` with the less privileged `incus` group to provide unprivileged users with an isolated restricted access to Incus. Such users may be able to create a custom storage volume with the necessary property (depending on kernel and filesystem support) and can then write a setuid binary from within the container which can be executed as an unprivileged user on the host to gain root privileges. A patch for this issue is expected in versions 6.0.6 and 6.19.0. As a workaround, permissions can be manually restricted until a patched version of Incus is deployed.

CVSS3: 7.8
0%
Низкий
2 месяца назад
debian логотип
CVE-2025-64507

Incus is a system container and virtual machine manager. An issue in v ...

CVSS3: 7.8
0%
Низкий
2 месяца назад
github логотип
GHSA-56mx-8g9f-5crf

Incus vulnerable to local privilege escalation through custom storage volumes

0%
Низкий
2 месяца назад
fstec логотип
BDU:2025-16114

Уязвимость системы управления контейнерами и менеджера виртуальных машин Incus, связанная с небезопасным управлением привилегиями, позволяющая нарушителю повысить свои привилегии

CVSS3: 8.4
0%
Низкий
2 месяца назад
redos логотип
ROS-20251216-7352

Уязвимость incus

CVSS3: 8.4
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу