Nil-Pointer Dereference in Incus System Container and Virtual Machine Manager
CVE-2026-47753

4.4MEDIUM

Key Information:

Vendor

Lxc

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-47753?

Prior to version 7.1.0, Incus, a system container and virtual machine manager, is vulnerable to a nil-pointer dereference during the instance creation process. An authenticated user with permissions can trigger this vulnerability remotely by uploading a specially crafted backup tarball. The flaw resides in the CreateInstanceFromBackup function found in internal/server/storage/backend.go, leading to a crash of the Incus daemon and resulting in denial of service for all projects running on the affected cluster member. This issue is associated with similar vulnerabilities documented in other advisories.

Affected Version(s)

incus < 7.1.0

References

CVSS V4

Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.