Privilege Escalation Vulnerability in Incus by LXD
CVE-2026-33945
10CRITICAL
What is CVE-2026-33945?
Incus, a system container and virtual machine manager, allows configurations to be passed to systemd within guest instances. Prior to version 6.23.0, a vulnerability existed where attackers could manipulate a configuration key to write outside the intended 'credentials' directory, potentially leading to unauthorized file writing as root. While direct data reading is not possible through this exploit, the ability to write arbitrary files raises significant concerns for both privilege escalation and denial of service attacks. Version 6.23.0 addresses and mitigates this vulnerability.
Affected Version(s)
incus < 6.23.0
