{"cves":[{"id":"CVE-2026-62941","published":"2026-08-21T15:16:00","updated_at":"2026-09-02T21:06:17.590070+00:00","description":"\nIncus is a system container and virtual machine manager. Prior to version\n7.3.0, when copying an instance across projects, the project restriction\ncheck (`AllowInstanceCreation`) runs BEFORE the source instance's\nconfiguration is merged into the request. Dangerous configuration keys\n(including `security.privileged`, `raw.lxc`, `raw.apparmor`) from the\nsource instance are merged AFTER the check passes, bypassing all project\nrestrictions on the target project. Version 7.3.0 patches the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.9,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-62941","https://github.com/lxc/incus/security/advisories/GHSA-mq9x-prm8-3vpw","https://github.com/lxc/incus/pull/3750"],"bugs":[""],"patches":{"incus":[]},"tags":{},"packages":[{"name":"incus","source":"https://ubuntu.com/security/cve?package=incus","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=incus","debian":"https://tracker.debian.org/pkg/incus","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.1-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-62940","published":"2026-08-21T15:16:00","updated_at":"2026-09-02T21:05:41.490998+00:00","description":"\nIncus is a system container and virtual machine manager. Prior to version\n7.3.0, when migrating an instance to another cluster member, user-supplied\nconfiguration overrides (including security-critical keys like\n`security.privileged` and `raw.lxc`) are applied without any project\nrestriction enforcement, allowing a restricted project user to escalate to\na privileged container and escape to the host. Version 7.3.0 patches the\nissue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.9,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-62940","https://github.com/lxc/incus/security/advisories/GHSA-qw5c-v953-38gw","https://github.com/lxc/incus/pull/3750"],"bugs":[""],"patches":{"incus":[]},"tags":{},"packages":[{"name":"incus","source":"https://ubuntu.com/security/cve?package=incus","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=incus","debian":"https://tracker.debian.org/pkg/incus","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.1-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-62867","published":"2026-08-21T15:16:00","updated_at":"2026-09-02T21:05:12.662882+00:00","description":"\nIncus is a system container and virtual machine manager. Prior to version\n7.3.0, improper validation of user-provided `block.create_options` in\nstorage volume configuration leads to argument injection in the constructed\nfilesystem creation command line. This allows a project-scoped user to\ninject arbitrary arguments into the binary executed as root. Version 7.3.0\npatches the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.9,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-62867","https://github.com/lxc/incus/security/advisories/GHSA-q7xw-r4w2-2wcm","https://github.com/lxc/incus/pull/3750"],"bugs":[""],"patches":{"incus":[]},"tags":{},"packages":[{"name":"incus","source":"https://ubuntu.com/security/cve?package=incus","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=incus","debian":"https://tracker.debian.org/pkg/incus","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.1-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-62313","published":"2026-08-21T15:16:00","updated_at":"2026-09-02T21:06:38.979560+00:00","description":"\nIncus is a system container and virtual machine manager. Prior to version\n7.3.0, project-level enforcement of\n`restricted.containers.privilege=isolated` can be trivially bypassed,\nallowing a user to create a non-isolated (shared host idmap) container in a\nproject that is configured to forbid them. The restriction only rejects an\nexplicitly set `security.idmap.isolated=false` (or empty) and fails to\nenforce anything when the key is omitted entirely. Because an unset\n`security.idmap.isolated` defaults to `false` (non-isolation), a user\nsimply leaves the key out and obtains exactly the container state the\nrestriction is meant to forbid. This defeats the tenant-isolation guarantee\nthe restriction exists to provide. Containers in the project share the host\nuid/gid map instead of receiving unique, non-overlapping ranges, weakening\nthe isolation boundary between co-tenant containers and the host. Version\n7.3.0 patches the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-62313","https://github.com/lxc/incus/security/advisories/GHSA-53cg-qvg7-m8vg","https://github.com/lxc/incus/pull/3750"],"bugs":[""],"patches":{"incus":[]},"tags":{},"packages":[{"name":"incus","source":"https://ubuntu.com/security/cve?package=incus","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=incus","debian":"https://tracker.debian.org/pkg/incus","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.1-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-55622","published":"2026-08-21T15:16:00","updated_at":"2026-09-02T21:05:12.662882+00:00","description":"\nIncus is a system container and virtual machine manager. Prior to version\n7.2.0, missing authorization checks exist for instance copying where an\nattacker knowing the name of a project that they don't have access to and\nthe name of an instance in that project can copy the instance to a new\nproject. This issue could allow an attacker to access secrets in instances\nthey are not authorized to access. Version 7.2.0 patches the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-55622","https://github.com/lxc/incus/security/advisories/GHSA-c9f5-j9c3-mhrg","https://github.com/lxc/incus/commit/1e3ffc53a10950e55de62ac1e0d612be597b84eb (v7.2.0)","https://github.com/canonical/lxd/pull/18603"],"bugs":[""],"patches":{"incus":[],"lxd":[]},"tags":{},"packages":[{"name":"incus","source":"https://ubuntu.com/security/cve?package=incus","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=incus","debian":"https://tracker.debian.org/pkg/incus","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.0-5","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"lxd","source":"https://ubuntu.com/security/cve?package=lxd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lxd","debian":"https://tracker.debian.org/pkg/lxd","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-55621","published":"2026-08-21T15:16:00","updated_at":"2026-09-02T21:05:28.156375+00:00","description":"\nIncus is a system container and virtual machine manager. Prior to version\n7.2.0, missing authorization checks exist for custom volume copying where\nan attacker knowing the name of a project that they don't have access to\nand the name of a custom volume in that project can copy the custom volume\nto a new project. This issue could allow an attacker to access secrets in\ncustom volumes they are not authorized to access. Version 7.2.0 patches the\nissue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-55621","https://github.com/lxc/incus/security/advisories/GHSA-64f3-v33m-w89f","https://github.com/lxc/incus/commit/2e01078366e2653712719dec82318e51c6d21b28 (v7.2.0)","https://github.com/canonical/lxd/pull/18603"],"bugs":[""],"patches":{"incus":[],"lxd":[]},"tags":{},"packages":[{"name":"incus","source":"https://ubuntu.com/security/cve?package=incus","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=incus","debian":"https://tracker.debian.org/pkg/incus","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.0-5","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"lxd","source":"https://ubuntu.com/security/cve?package=lxd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lxd","debian":"https://tracker.debian.org/pkg/lxd","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-48769","published":"2026-08-21T15:16:00","updated_at":"2026-09-02T21:04:54.377938+00:00","description":"\nIncus is a system container and virtual machine manager. Prior to version\n7.2.0, an arbitrary file write exists in the Incus client when a malicious\nimage server returns a crafted `Incus-Image-Hash` header. This can lead to\narbitrary command execution as root on the server. Version 7.2.0 patches\nthe issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.9,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48769","https://github.com/lxc/incus/security/advisories/GHSA-f6m5-xw2g-xc4x","https://github.com/lxc/incus/commit/46d6ef232186df5535c49ca9f3597cab381f9b86 (v7.2.0)","https://github.com/canonical/lxd/pull/18594"],"bugs":[""],"patches":{"incus":[],"lxd":[]},"tags":{},"packages":[{"name":"incus","source":"https://ubuntu.com/security/cve?package=incus","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=incus","debian":"https://tracker.debian.org/pkg/incus","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.0-5","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"lxd","source":"https://ubuntu.com/security/cve?package=lxd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lxd","debian":"https://tracker.debian.org/pkg/lxd","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-48756","published":"2026-08-21T15:16:00","updated_at":"2026-09-02T21:05:41.490998+00:00","description":"\nIncus is a system container and virtual machine manager. Prior to version\n7.1.0, `(*backend).CreateCustomVolumeFromBackup` in\n`internal/server/storage/backend.go` contains an unguarded `*time.Time`\ndereference on the `ExpiresAt` field of every volume-snapshot entry in an\nimported custom-volume backup. An authenticated user with\n`can_create_storage_volumes` permission on any project can crash the\n`incusd` daemon by uploading a backup tarball whose\n`volume_snapshots[*].expires_at` field is absent. This is a sibling-field\nvariant of GHSA-r7w7-mmxr-47r9 (CVE-2026-40197). Commit\n`985a1dedf9f3e7ba729c93b654905ed510de25c2` added `if s == nil` at the top\nof the loop body, but did not guard the adjacent `*snapshot.ExpiresAt`\nderef 19 lines later. Every other consumer of\n`Config.VolumeSnapshots[i].ExpiresAt` in this same file already gates the\nderef with a nil-check — the asymmetric guard is the bug. Version 7.1.0\ncontains an updated patch.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":2.1,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48756","https://github.com/lxc/incus/pull/3425","https://github.com/lxc/incus/security/advisories/GHSA-xhqx-mgh3-3h7q"],"bugs":[""],"patches":{"incus":[],"lxd":[]},"tags":{},"packages":[{"name":"incus","source":"https://ubuntu.com/security/cve?package=incus","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=incus","debian":"https://tracker.debian.org/pkg/incus","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.0-2","component":null,"pocket":"security"}]},{"name":"lxd","source":"https://ubuntu.com/security/cve?package=lxd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lxd","debian":"https://tracker.debian.org/pkg/lxd","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-48755","published":"2026-08-21T15:16:00","updated_at":"2026-09-02T21:04:30.100833+00:00","description":"\nIncus is a system container and virtual machine manager. Prior to version\n7.1.0, improper validation of user-provided backup compression algorithm\nleads to argument injection in the constructed command line. This leads to\nan arbitrary file write on the host, possibly leading to arbitrary command\nexecution. Version 7.1.0 patches the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.9,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48755","https://github.com/lxc/incus/security/advisories/GHSA-v6mj-8pf4-hhw4","https://github.com/lxc/incus/commit/873a032a461df6b09b7586435b592873863a4e88 (v7.2.0)","https://github.com/canonical/lxd/pull/18597"],"bugs":[""],"patches":{"incus":[],"lxd":[]},"tags":{},"packages":[{"name":"incus","source":"https://ubuntu.com/security/cve?package=incus","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=incus","debian":"https://tracker.debian.org/pkg/incus","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.0-5","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"lxd","source":"https://ubuntu.com/security/cve?package=lxd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lxd","debian":"https://tracker.debian.org/pkg/lxd","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-48754","published":"2026-08-21T15:16:00","updated_at":"2026-09-02T21:04:30.100833+00:00","description":"\nIncus is a system container and virtual machine manager. Prior to version\n7.1.0, `(*backend).createDependentVolumesFromBackup` in\n`internal/server/storage/backend.go` contains a cluster of unguarded\npointer derefs on every dependent-volume entry's `VolumeSnapshots[i]`,\n`Volume`, and `Pool` sub-fields. An authenticated user with\n`can_create_instances` permission on any project can crash the `incusd`\ndaemon by uploading an instance backup tarball whose `dependent_volumes[*]`\nblock contains a nil snapshot pointer (or omits `volume:` / `pool:`). This\nis a sibling-field variant of the 2026-05-04 batch fix\n`d768f81c0a1d985f35ae56219519822b080bf5e3` (\"Properly check dependent\nvolumes on import\"). That commit added `if disk == nil` at the top of the\nouter loop, but did not guard the four sub-pointer fields the loop body\ndereferences naked. Version 7.1.0 contains an updated patch.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":2.1,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48754","https://github.com/lxc/incus/pull/3425","https://github.com/lxc/incus/security/advisories/GHSA-4xg6-52mh-fpw8"],"bugs":[""],"patches":{"incus":[]},"tags":{},"packages":[{"name":"incus","source":"https://ubuntu.com/security/cve?package=incus","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=incus","debian":"https://tracker.debian.org/pkg/incus","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.0-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-48753","published":"2026-08-21T15:16:00","updated_at":"2026-09-02T21:04:46.842262+00:00","description":"\nIncus is a system container and virtual machine manager. Prior to version\n7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and\nallows creation of arbitrary files on the host. This behavior could lead to\narbitrary command execution. Version 7.1.0 fixes the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.9,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48753","https://github.com/lxc/incus/pull/3425","https://github.com/lxc/incus/security/advisories/GHSA-ccjc-4qc3-jxqc"],"bugs":[""],"patches":{"incus":[]},"tags":{},"packages":[{"name":"incus","source":"https://ubuntu.com/security/cve?package=incus","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=incus","debian":"https://tracker.debian.org/pkg/incus","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.0-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-48752","published":"2026-08-21T15:16:00","updated_at":"2026-09-02T21:04:16.246713+00:00","description":"\nIncus is a system container and virtual machine manager. Prior to version\n7.2.0, a specially crafted image or instance backup can be used to read or\ncreate/write arbitrary files on the host; possibly leading to arbitrary\ncommand execution. Version 7.2.0 patches the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.9,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48752","https://github.com/lxc/incus/security/advisories/GHSA-vxp5-584q-c479","https://github.com/lxc/incus/commit/cbefa31ae0da8fd96361178aed3a3c631e098fef (v7.2.0)","https://github.com/canonical/lxd/pull/18590"],"bugs":[""],"patches":{"incus":[],"lxd":[]},"tags":{},"packages":[{"name":"incus","source":"https://ubuntu.com/security/cve?package=incus","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=incus","debian":"https://tracker.debian.org/pkg/incus","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.0-5","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"lxd","source":"https://ubuntu.com/security/cve?package=lxd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lxd","debian":"https://tracker.debian.org/pkg/lxd","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-48751","published":"2026-08-21T15:16:00","updated_at":"2026-09-02T21:04:30.100833+00:00","description":"\nIncus is a system container and virtual machine manager. Prior to version\n7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block`\nsetting; allowing for arbitrary command execution on the Incus server by\nabusing lowlevel hooks such as `raw.lxc` and `raw.qemu`. Version 7.2.0\npatches the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.9,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48751","https://github.com/lxc/incus/security/advisories/GHSA-48q5-w887-33wv","https://github.com/canonical/lxd/pull/18604"],"bugs":[""],"patches":{"incus":[],"lxd":[]},"tags":{},"packages":[{"name":"incus","source":"https://ubuntu.com/security/cve?package=incus","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=incus","debian":"https://tracker.debian.org/pkg/incus","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.0-5","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"lxd","source":"https://ubuntu.com/security/cve?package=lxd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lxd","debian":"https://tracker.debian.org/pkg/lxd","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-48750","published":"2026-08-21T15:16:00","updated_at":"2026-09-02T21:05:34.820383+00:00","description":"\nIncus is a system container and virtual machine manager. Prior to version\n7.2.0, the `record-output` parameter of the `/instances/$name/exec`\nendpoint stores the output of the command in the `exec-output` directory of\nthe instance. If `exec-output` is a symlink, file named `exec_UUID.stdout`\nand `exec_UUID.stderr` can be written to an arbitrary location where the\n`.stdout` file will contain arbitrary content. This behavior can be abused\nfor arbitrary command execution. Version 7.2.0 contains a patch.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.9,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48750","https://github.com/lxc/incus/security/advisories/GHSA-73hr-m85f-64v9","https://github.com/canonical/lxd/pull/18590"],"bugs":[""],"patches":{"incus":[],"lxd":[]},"tags":{},"packages":[{"name":"incus","source":"https://ubuntu.com/security/cve?package=incus","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=incus","debian":"https://tracker.debian.org/pkg/incus","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.0-5","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"lxd","source":"https://ubuntu.com/security/cve?package=lxd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lxd","debian":"https://tracker.debian.org/pkg/lxd","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-48749","published":"2026-08-21T15:16:00","updated_at":"2026-09-02T21:04:16.246713+00:00","description":"\nIncus is a system container and virtual machine manager. Prior to version\n7.2.0, a specially crafted image can be used to read or create/write\narbitrary files on the host; possibly leading to arbitrary command\nexecution. Version 7.2.0 fixes the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.9,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48749","https://github.com/lxc/incus/security/advisories/GHSA-2q3f-q5pq-g8wv","https://github.com/canonical/lxd/pull/18590"],"bugs":[""],"patches":{"incus":[],"lxd":[]},"tags":{},"packages":[{"name":"incus","source":"https://ubuntu.com/security/cve?package=incus","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=incus","debian":"https://tracker.debian.org/pkg/incus","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.0-5","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"lxd","source":"https://ubuntu.com/security/cve?package=lxd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lxd","debian":"https://tracker.debian.org/pkg/lxd","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47753","published":"2026-08-21T15:16:00","updated_at":"2026-09-02T21:04:23.398185+00:00","description":"\nIncus is a system container and virtual machine manager. Prior to version\n7.1.0, `(*backend).CreateInstanceFromBackup` in\n`internal/server/storage/backend.go` contains a nil-pointer dereference\nthat an authenticated user with permission to create instances in any\nproject can trigger remotely by uploading a crafted backup tarball. The\nIncus daemon panics and the process crashes, causing denial of service to\nevery project on that cluster member. This is a sibling of\n`GHSA-fwj8-62r8-8p8m`, `GHSA-r7w7-mmxr-47r9`, and `GHSA-x5r6-jr56-89pv`\n(all assigned 2026-05-04). Those patches added guards on adjacent fields of\nthe same `backup/config.Config` struct; the `Volume` field on the\ninstance-import path was missed. Version 7.1.0 contains an updated patch.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":4.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47753","https://github.com/lxc/incus/pull/3425","https://github.com/lxc/incus/security/advisories/GHSA-8g7m-96c8-8wwc"],"bugs":[""],"patches":{"incus":[]},"tags":{},"packages":[{"name":"incus","source":"https://ubuntu.com/security/cve?package=incus","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=incus","debian":"https://tracker.debian.org/pkg/incus","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.0-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-77806","published":"2026-08-21T14:16:00","updated_at":"2026-09-02T21:11:46.419281+00:00","description":"\nSPIP before 4.4.21 allows unauthenticated remote attackers to execute\narbitrary code, as exploited in the wild in August 2026. This is related to\ncode injection via an X-Spip-Filtre HTTP request header that is mishandled\nby analyse_resultat_skel.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-77806","https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-21.html"],"bugs":[""],"patches":{"spip":[]},"tags":{},"packages":[{"name":"spip","source":"https://ubuntu.com/security/cve?package=spip","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=spip","debian":"https://tracker.debian.org/pkg/spip","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4.21+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-15576","published":"2026-08-21T11:17:00","updated_at":"2026-09-02T21:02:13.773510+00:00","description":"\nImproper authentication in the agent receiver of Checkmk <2.5.0p10 allows\nan unauthenticated remote attacker to bypass mutual TLS client certificate\nverification of relay endpoints by supplying a fixed placeholder identity\nin the request URL, resulting in limited impact on integrity and\navailability. Only the Cloud, Ultimate and Ultimate MT editions are\naffected, as other editions do not expose relay endpoints.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-15576"],"bugs":[""],"patches":{"check-mk":[]},"tags":{},"packages":[{"name":"check-mk","source":"https://ubuntu.com/security/cve?package=check-mk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=check-mk","debian":"https://tracker.debian.org/pkg/check-mk","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-77651","published":"2026-08-21T01:17:00","updated_at":"2026-09-02T21:10:40.314593+00:00","description":"\nThe arrayref crate 0.3.10 for Rust can trigger execution of malicious code\nwhen compiling a project that uses the crate, because it has a rogue\ndependency that registers with a command-and-control server to offer\narbitrary code execution.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-77651","https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/","https://rustsec.org/advisories/RUSTSEC-2026-0260.html"],"bugs":[""],"patches":{"rust-arrayref":[]},"tags":{},"packages":[{"name":"rust-arrayref","source":"https://ubuntu.com/security/cve?package=rust-arrayref","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rust-arrayref","debian":"https://tracker.debian.org/pkg/rust-arrayref","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Only affected compromised and published 0.3.10 version","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-77650","published":"2026-08-21T01:17:00","updated_at":"2026-09-02T21:12:32.374212+00:00","description":"\nThe append-only-vec crate 0.1.9 for Rust can trigger execution of malicious\ncode when compiling a project that uses the crate, because it has a rogue\ndependency that registers with a command-and-control server to offer\narbitrary code execution.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-77650","https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref","https://rustsec.org/advisories/RUSTSEC-2026-0262.html"],"bugs":[""],"patches":{"rust-append-only-vec":[]},"tags":{},"packages":[{"name":"rust-append-only-vec","source":"https://ubuntu.com/security/cve?package=rust-append-only-vec","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rust-append-only-vec","debian":"https://tracker.debian.org/pkg/rust-append-only-vec","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Only affects compromised and published 0.1.9 version","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":3340,"limit":20,"total_results":79316}