Junglewise Threat Intelligence

CVE-2026-63125: Incus arbitrary file write via backup.yaml symlink

CVE-2026-63125 · Severity: critical · CVSS 9.9 · Published 2026-08-21

Technologies: Linux Containers Incus.

Executive brief

Incus is a container and virtual machine management system used by system administrators to provision and manage workloads. An unprivileged user with basic image and instance creation permissions can exploit a symlink vulnerability in backup file handling to write arbitrary files as root on the host system, leading to complete compromise of the Incus host and all tenants running on it.

Technical details

The vulnerability is a symlink-following bug (CWE-59/CWE-61) in Incus's backup file handling. When unpacking a crafted image, the daemon extracts a metadata tarball containing a symlinked backup.yaml into the instance directory. Later, UpdateInstanceBackupFile() creates the backup.yaml file without checking for symlinks (no O_NOFOLLOW flag) and follows the link to write instance configuration data as root. An unprivileged user with can_create_images and can_create_instances permissions can craft a malicious image where backup.yaml symlinks to /etc/ld.so.preload, then include an attacker-controlled shared library in the image and reference it via instance config. This causes arbitrary code execution as root when the next system process runs. The attack requires network access to the Incus API and valid project-confined credentials. Version 7.3.0 and later patch the issue by validating and rejecting symlinks during image unpacking.

Affected products

  • Linux Containers Incus prior to 7.3.0

Timeline

  • 2026-07-30: disclosed: GitHub security advisory published
  • 2026-08-21: advisory: NVD entry published
  • 2026-07-30: patched: Fixed in version 7.3.0

References