Multiple security issues were discovered in Incus, a system container and virtual machine manager, which could result in denial of service, For the stable distribution (trixie), these problems have been fixed in version 6.0.4-2+deb13u7. We recommend that you upgrade your incus packages.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6244-1
Remove incus dependency from incus-agent. Update to 6.23. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-4481307278 2026-04-20 01:04:24.758007+00:00 -------------------------------------------------------------------------------- Name : incus Product : Fedora 42 Version : 6.23 Release : 3.fc42 URL : https://linuxcontainers.org/incus Summary : Powerful system container and virtual machine manager Description : Container hypervisor based on LXC Incus offers a REST API to remotely manage containers over the network, using an image based work-flow and with support for live migration. This package contains the Incus daemon. -------------------------------------------------------------------------------- Update Information: Remove incus dependency from incus-agent. Update to 6.23 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 9 2026 Carl George - 6.23-3 - Remove incus dependency from incus-agent rhbz#2456888 * Mon Apr 6 2026 Reto Gantenbein - 6.23-2 - Fix static builds of vendored dependencies (RHBZ 2419661) * Mon Apr 6 2026 Reto Gantenbein - 6.23-1 - Update to 6.23 * Mon Mar 30 2026 Neal Gompa - 6.19.1-4 - Drop selinux subpackage in favor of container-selinux * Tue Feb 3 2026 Maxwell G - 6.19.1-3 - Rebuild for https://fedoraproject.org/wiki/Changes/golang1.26 * Fri Jan 16 2026 Fedora Release Engineering - 6.19.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2390870 - incus: go-viper's mapstructure May Leak Sensitive Information in Logs [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2390870 [ 2 ] Bug #2398840 - CVE-2025-47910 incus: CrossOriginProtection bypass in net/http [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2398840 [3 ] Bug #2412795 - CVE-2025-58183 incus: Unbounded allocation when parsing GNU sparse map [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2412795 [ 4 ] Bug #2432454 - CVE-2026-23954 incus: container image templating arbitrary host file read and write [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2432454 [ 5 ] Bug #2432456 - CVE-2026-23953 incus: container environment configuration newline injection [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2432456 [ 6 ] Bug #2441165 - CVE-2025-69725 incus: Go-chi/chi: Open Redirect vulnerability allows redirection to malicious websites [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2441165 [ 7 ] Bug #2452041 - CVE-2026-33542 incus: Incus: Image cache poisoning due to insufficient image fingerprint validation [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2452041 [ 8 ] Bug #2452043 - CVE-2026-33897 incus: Incus: Arbitrary file read/write as root via pongo2 template chroot bypass [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2452043 [ 9 ] Bug #2452045 - CVE-2026-33711 incus: Incus: Local privilege escalation or denial of service via predictable temporary file paths [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2452045 [ 10 ] Bug #2452047 - CVE-2026-33743 incus: Incus: Denial of Service via specially crafted storage bucket backup [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2452047 [ 11 ] Bug #2452105 - CVE-2026-33898 incus: Incus: Privilege escalation and unauthorized access due to improper authentication token validation in web UI [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452105 [ 12 ] Bug #2456888 - Installing incus-agent installs the entire incus stack https://bugzilla.redhat.com/show_bug.cgi?id=2456888 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnfupgrade --advisory FEDORA-2026-4481307278' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Remove incus dependency from incus-agent. Update to 6.23. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-094b7621cf 2026-04-20 00:44:47.956847+00:00 -------------------------------------------------------------------------------- Name : incus Product : Fedora 43 Version : 6.23 Release : 3.fc43 URL : https://linuxcontainers.org/incus Summary : Powerful system container and virtual machine manager Description : Container hypervisor based on LXC Incus offers a REST API to remotely manage containers over the network, using an image based work-flow and with support for live migration. This package contains the Incus daemon. -------------------------------------------------------------------------------- Update Information: Remove incus dependency from incus-agent. Update to 6.23 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 9 2026 Carl George - 6.23-3 - Remove incus dependency from incus-agent rhbz#2456888 * Mon Apr 6 2026 Reto Gantenbein - 6.23-2 - Fix static builds of vendored dependencies (RHBZ 2419661) * Mon Apr 6 2026 Reto Gantenbein - 6.23-1 - Update to 6.23 * Mon Mar 30 2026 Neal Gompa - 6.19.1-4 - Drop selinux subpackage in favor of container-selinux * Tue Feb 3 2026 Maxwell G - 6.19.1-3 - Rebuild for https://fedoraproject.org/wiki/Changes/golang1.26 * Fri Jan 16 2026 Fedora Release Engineering - 6.19.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2412713 - CVE-2025-58183 incus: Unbounded allocation when parsing GNU sparse map [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2412713 [ 2 ] Bug #2419345 - incus-6.23.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2419345 [ 3 ] Bug #2419661 - incus-agent must bestatically linked for VM exec to work https://bugzilla.redhat.com/show_bug.cgi?id=2419661 [ 4 ] Bug #2432455 - CVE-2026-23954 incus: container image templating arbitrary host file read and write [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2432455 [ 5 ] Bug #2432457 - CVE-2026-23953 incus: container environment configuration newline injection [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2432457 [ 6 ] Bug #2436657 - Incus VMs do not boot due to unknown audio driver https://bugzilla.redhat.com/show_bug.cgi?id=2436657 [ 7 ] Bug #2441179 - CVE-2025-69725 incus: Go-chi/chi: Open Redirect vulnerability allows redirection to malicious websites [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2441179 [ 8 ] Bug #2452042 - CVE-2026-33542 incus: Incus: Image cache poisoning due to insufficient image fingerprint validation [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2452042 [ 9 ] Bug #2452044 - CVE-2026-33897 incus: Incus: Arbitrary file read/write as root via pongo2 template chroot bypass [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2452044 [ 10 ] Bug #2452046 - CVE-2026-33711 incus: Incus: Local privilege escalation or denial of service via predictable temporary file paths [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2452046 [ 11 ] Bug #2452048 - CVE-2026-33743 incus: Incus: Denial of Service via specially crafted storage bucket backup [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2452048 [ 12 ] Bug #2452106 - CVE-2026-33945 incus: Incus: Privilege escalation and denial of service via path traversal in systemd credential configuration [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452106 [ 13 ] Bug #2456888 - Installing incus-agent installs the entire incus stack https://bugzilla.redhat.com/show_bug.cgi?id=2456888 -------------------------------------------------------------------------------- This update canbe installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-094b7621cf' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Two security issues were discovered in Incus, a system container and virtual machine manager, which could result in restriction bypass or privilege escalation. For the stable distribution (trixie), these problems have been fixed in version 6.0.4-2+deb13u6.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6212-1
An update that solves 6 vulnerabilities can now be installed.. # incus-6.23-1.1 on GA media Announcement ID: openSUSE-SU-2026:10450-1 Rating: moderate Cross-References: * CVE-2026-33542 * CVE-2026-33711 * CVE-2026-33743 * CVE-2026-33897 * CVE-2026-33898 * CVE-2026-33945 CVSS scores: * CVE-2026-33542 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:N * CVE-2026-33897 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-33945 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Tumbleweed An update that solves 6 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the incus-6.23-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * incus 6.23-1.1 * incus-bash-completion 6.23-1.1 * incus-fish-completion 6.23-1.1 * incus-tools 6.23-1.1 * incus-zsh-completion 6.23-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33542.html * https://www.suse.com/security/cve/CVE-2026-33711.html * https://www.suse.com/security/cve/CVE-2026-33743.html * https://www.suse.com/security/cve/CVE-2026-33897.html * https://www.suse.com/security/cve/CVE-2026-33898.html * https://www.suse.com/security/cve/CVE-2026-33945.html . Learn about the openSUSE update for incus version 6.23-1.1 addressing multiple security issues with moderate severity.. openSUSE Tumbleweed, incus 6.23-1.1, moderate security update. . LinuxSecurity.com Team
Multiple security issues were discovered in Incus, a system container and virtual machine manager, which could result in denial of service or the execution of arbitrary commands. For the stable distribution (trixie), these problems have been fixed in version 6.0.4-2+deb13u5.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6184-1
An update that solves 2 vulnerabilities can now be installed.. # incus-6.22-1.1 on GA media Announcement ID: openSUSE-SU-2026:10280-1 Rating: moderate Cross-References: * CVE-2026-23953 * CVE-2026-23954 Affected Products: * openSUSE Tumbleweed An update that solves 2 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the incus-6.22-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * incus 6.22-1.1 * incus-bash-completion 6.22-1.1 * incus-fish-completion 6.22-1.1 * incus-tools 6.22-1.1 * incus-zsh-completion 6.22-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23953.html * https://www.suse.com/security/cve/CVE-2026-23954.html . Two vulnerabilities fixed in Incus 6.22-1.1 enhance openSUSE Tumbleweed's security. Immediate update recommended.. openSUSE Tumbleweed, Incus 6.22-1.1, security patch. . LinuxSecurity.com Team
Two security issues were discovered in Incus, a system container and virtual machine manager, which could result the in execution of arbitrary commands via malformed images. For the stable distribution (trixie), these problems have been fixed in version 6.0.4-2+deb13u4.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6109-1
Get the latest Linux and open source security news straight to your inbox.