Bug 2521024 (CVE-2026-63343)
| Summary: | CVE-2026-63343 incus: Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | urgent | Docs Contact: | |
| Priority: | urgent | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Incus, a system container and virtual machine manager. An authenticated Incus user can exploit this vulnerability by providing a malicious image containing a `metadata.yaml` symlink that points to an arbitrary host path. This allows the user to read or overwrite any file on the host with root privileges via the instance metadata API. This issue stems from improper handling of `metadata.yaml` symlinks, which was not included in prior patches for similar vulnerabilities.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2531513 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-08-21 15:30:56 UTC
|