Bug 2521985 - CVE-2026-62313 incus: Incus: Project restriction bypass weakens container isolation [fedora-all]
Summary: CVE-2026-62313 incus: Incus: Project restriction bypass weakens container iso...
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: incus
Version: rawhide
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Neal Gompa
QA Contact:
URL:
Whiteboard: {"flaws": ["7715374b-8232-4819-9b62-d...
Depends On:
Blocks: CVE-2026-62313
TreeView+ depends on / blocked
 
Reported: 2026-08-24 15:00 UTC by Laura Pardo
Modified: 2026-08-24 15:00 UTC (History)
7 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Laura Pardo 2026-08-24 15:00:00 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Incus is a system container and virtual machine manager. Prior to version 7.3.0, project-level enforcement of `restricted.containers.privilege=isolated` can be trivially bypassed, allowing a user to create a non-isolated (shared host idmap) container in a project that is configured to forbid them. The restriction only rejects an explicitly set `security.idmap.isolated=false` (or empty) and fails to enforce anything when the key is omitted entirely. Because an unset `security.idmap.isolated` defaults to `false` (non-isolation), a user simply leaves the key out and obtains exactly the container state the restriction is meant to forbid. This defeats the tenant-isolation guarantee the restriction exists to provide. Containers in the project share the host uid/gid map instead of receiving unique, non-overlapping ranges, weakening the isolation boundary between co-tenant containers and the host. Version 7.3.0 patches the issue.


Note You need to log in before you can comment on or make changes to this bug.