Image Cache Poisoning Vulnerability in Incus by LXC
CVE-2026-33542

5.7MEDIUM

Key Information:

Vendor

Lxc

Status
Vendor
CVE Published:
26 March 2026

What is CVE-2026-33542?

Incus, a system container and virtual machine manager, has a vulnerability due to insufficient validation of image fingerprints when downloading from simplestreams image servers. This may lead to image cache poisoning, potentially causing other tenants to unknowingly execute images controlled by attackers instead of the intended images. The issue has been addressed in version 6.23.0, which eliminates this risk.

Affected Version(s)

incus < 6.23.0

References

CVSS V4

Score:
5.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.