Executive brief
Incus is a system container and virtual machine manager. A flaw in how it validates user input for storage volume configuration allows a project member (not requiring admin access) to inject arbitrary arguments into filesystem creation commands that run as root. An attacker could read sensitive files, corrupt filesystems, or potentially execute arbitrary code.
Technical details
The vulnerability is an argument injection flaw (CWE-88) in the storage volume configuration parsing. The `block.create_options` parameter is validated using `validate.IsAny` (no validation), retrieved from the volume config, and passed directly to filesystem creation binaries via `strings.Fields()` and `subprocess.TryRunCommand()`. A project-scoped user with `can_create_storage_volumes` permission can inject arbitrary flags. The injected arguments execute with root privileges when the volume is formatted. Exploitation requires only project-level access (not server admin), and no user interaction. Fixed in version 7.3.0.
Affected products
- LXC Incus prior to 7.3.0
Timeline
- 2026-07-30: disclosed: GitHub security advisory published
- 2026-07-30: patched: Fixed in version 7.3.0
- 2026-08-21: advisory: CVE-2026-62867 published