Error Handling Flaw in Incus System Container Manager
CVE-2026-41647

6.5MEDIUM

Key Information:

Vendor

Lxc

Status
Vendor
CVE Published:
7 May 2026

What is CVE-2026-41647?

Prior to version 7.0.0, Incus, a system container and virtual machine manager, lacked adequate error handling. This flaw permitted authenticated users to trigger a crash of the daemon by importing a truncated storage bucket backup file. This critical issue has since been addressed in version 7.0.0, reinforcing the stability and reliability of the software.

Affected Version(s)

incus < 7.0.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.