Executive brief
Incus is a container and virtual machine management tool. A vulnerability allows an attacker to use a specially crafted container image to write files to the host operating system's filesystem. This could allow an attacker to gain full control over the host server, potentially leading to data theft or service disruption.
Technical details
A vulnerability in Incus (specifically the incusd component) exists where the 'record-output' parameter of the /instances/$name/exec endpoint fails to properly validate the 'exec-output' directory. If a crafted image contains a top-level symlink named 'exec-output' pointing to a host directory (e.g., /etc/cron.d), the 'os.OpenFile' function follows this symlink when recording command output. An attacker with low privileges can trigger this by launching an instance from a malicious image and executing a command with output recording enabled. This results in the creation of .stdout and .stderr files on the host, which can be leveraged for arbitrary command execution on the host system. The issue is fixed in version 7.2.0.
Affected products
- LXC Incus < 7.2.0
Timeline
- 2026-06-25: disclosed
- 2026-06-26: advisory: GHSA-73hr-m85f-64v9 published
- 7.2.0: patched