Executive brief
Incus, a container and virtual machine management tool, is vulnerable to a flaw where a specially crafted container image or backup can be used to read or write any file on the host server. An attacker with the ability to import images or backups could use this to modify critical system files, potentially leading to full control over the host machine and its operations. This poses a significant risk to data confidentiality and system availability.
Technical details
A path traversal vulnerability exists in Incus due to improper sanitization of symlinks within container images and instance backups. For container images, the 'archive.Unpack' function fails to reject top-level 'templates' symlinks during extraction. For instance backups, the 'rsync.LocalCopy' operation uses archive mode without the '--safe-links' flag, allowing a 'templates' symlink to point to arbitrary locations on the host filesystem. An attacker with low privileges can exploit this by importing a malicious image or backup, then using the template management commands to read from or write to host files (e.g., /etc/cron.d). This can lead to arbitrary command execution with root privileges on the host. The issue is fixed in version 7.2.0.
Affected products
- Linux Containers (LXC) Incus < 7.2.0
Timeline
- 2026-06-25: disclosed
- 2026-06-26: advisory
- 2026-06-26: patched