Bug 2467507 (CVE-2026-40195) - CVE-2026-40195 incus: Incus: Denial of Service via malformed backup metadata import
Summary: CVE-2026-40195 incus: Incus: Denial of Service via malformed backup metadata ...
Keywords:
Status: NEW
Alias: CVE-2026-40195
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2476739
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-06 21:02 UTC by OSIDB Bzimport
Modified: 2026-05-12 19:33 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-05-06 21:02:40 UTC
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage bucket import logic allows an authenticated user with access to the storage bucket feature to cause the Incus daemon to crash. The vulnerability is present in the backup metadata handling logic, where the daemon processes the index.yaml file from an imported archive and accesses members of the parsed backup configuration without first verifying that the configuration object was initialized. A malicious or malformed index.yaml that omits the config block causes a nil-pointer dereference during bucket import operations and terminates the daemon. Repeated use of this issue can be used to keep Incus offline, causing a denial of service. This issue is fixed in version 7.0.0.


Note You need to log in before you can comment on or make changes to this bug.