Inadequate Container Isolation in Incus by LXC
CVE-2026-62313
4.3MEDIUM
What is CVE-2026-62313?
Incus, a system container and virtual machine manager by LXC, suffers from inadequate enforcement of project-level security settings. Before version 7.3.0, the restriction meant to enforce isolated container deployment can be bypassed with ease. The mechanism fails to properly validate the security.idmap.isolated key, allowing users to create containers without the designated isolation features. This oversight results in multiple containers sharing the host's user ID and group ID mappings, thus compromising the isolation intended between tenants. Such vulnerabilities weaken security postures and could expose systems to potential risks during multi-tenant operation.
Affected Version(s)
incus < 7.3.0
