Nil-Pointer Dereference in Incus System Container and Virtual Machine Manager
CVE-2026-47753
4.4MEDIUM
What is CVE-2026-47753?
Prior to version 7.1.0, Incus, a system container and virtual machine manager, is vulnerable to a nil-pointer dereference during the instance creation process. An authenticated user with permissions can trigger this vulnerability remotely by uploading a specially crafted backup tarball. The flaw resides in the CreateInstanceFromBackup function found in internal/server/storage/backend.go, leading to a crash of the Incus daemon and resulting in denial of service for all projects running on the affected cluster member. This issue is associated with similar vulnerabilities documented in other advisories.
Affected Version(s)
incus < 7.1.0
