Bug 2521024 (CVE-2026-63343)

Summary: CVE-2026-63343 incus: Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: urgent Docs Contact:
Priority: urgent    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Incus, a system container and virtual machine manager. An authenticated Incus user can exploit this vulnerability by providing a malicious image containing a `metadata.yaml` symlink that points to an arbitrary host path. This allows the user to read or overwrite any file on the host with root privileges via the instance metadata API. This issue stems from improper handling of `metadata.yaml` symlinks, which was not included in prior patches for similar vulnerabilities.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2531513    
Bug Blocks:    

Description OSIDB Bzimport 2026-08-21 15:30:56 UTC
Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an authenticated Incus user to read or overwrite any file on the host as root via the instance metadata API. The `exec-output` and `templates/` paths were patched in a prior release using `Lstat` rejection and `os.OpenRoot` confinement; `metadata.yaml` was not included in either patch and remains exploitable. Version 7.3.0 patches the issue.