Unprotected Time Dereference in Incus Container Manager Affects Multiple Versions
CVE-2026-48756

2.1LOW

Key Information:

Vendor

Lxc

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-48756?

A vulnerability in the Incus container and virtual machine manager allows an authenticated user with specific permissions to crash the daemon by uploading a backup tarball with a missing expires_at field for volume snapshots. This flaw lies in the unguarded dereference of the ExpiresAt field in the code responsible for creating custom volumes from backups. The issue has been addressed in version 7.1.0, which includes necessary checks to prevent exploitation.

Affected Version(s)

incus < 7.1.0

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.