Remote Code Execution Vulnerability in Incus System Container Manager
CVE-2026-48754
2.1LOW
What is CVE-2026-48754?
The Incus system container and virtual machine manager is susceptible to a vulnerability related to unguarded pointer dereferences in the dependent-volume entry fields, such as VolumeSnapshots, Volume, and Pool. Authenticated users with the can_create_instances permission can exploit this flaw by uploading a specially crafted instance backup tarball that contains a nil snapshot pointer or lacks the required fields. This could lead to crashing the incusd daemon, resulting in disruptions for users. Version 7.1.0 addresses this vulnerability by implementing necessary checks to ensure safe dereferencing of pointers.
Affected Version(s)
incus < 7.1.0
