CVE 5.7 MEDIUM

Incus does not verify combined fingerprint when downloading images from simplestreams servers_CVE-2026-33542

5.7 / 10
MEDIUM
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N/E:P

Description

Incus is a system container and virtual machine manager. Prior to version 6.23.0, a lack of validation of the image fingerprint when downloading from simplestreams image servers opens the door to image cache poisoning and under very narrow circumstances exposes other tenants to running attacker controlled images rather than the expected one. Version 6.23.0 patches the issue.

Basic Information

ID CVE-2026-33542
Source GitHub_M
Published Mar 26, 2026 at 22:32
Modified Mar 30, 2026 at 11:47

Affected Product

Vendor lxc
Product incus
Version < 6.23.0
Affected Versions lxc incus < 6.23.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.