Unprotected Time Dereference in Incus Container Manager Affects Multiple Versions
CVE-2026-48756
2.1LOW
What is CVE-2026-48756?
A vulnerability in the Incus container and virtual machine manager allows an authenticated user with specific permissions to crash the daemon by uploading a backup tarball with a missing expires_at field for volume snapshots. This flaw lies in the unguarded dereference of the ExpiresAt field in the code responsible for creating custom volumes from backups. The issue has been addressed in version 7.1.0, which includes necessary checks to prevent exploitation.
Affected Version(s)
incus < 7.1.0
